
Related Posts Widget with Thumbnails Security & Risk Analysis
wordpress.org/plugins/advanced-css3-related-posts-widgetHere is wonderful plugin for displaying links to related posts beneath each
Is Related Posts Widget with Thumbnails Safe to Use in 2026?
Use With Caution
Score 64/100Related Posts Widget with Thumbnails has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'advanced-css3-related-posts-widget' plugin version 1.2 presents a mixed security posture. While the static analysis indicates a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events, and all SQL queries utilize prepared statements, significant concerns arise from output escaping and the vulnerability history.
The code analysis reveals a very low rate of proper output escaping (4%), meaning a substantial portion of output is potentially vulnerable to cross-site scripting (XSS) attacks. The absence of capability checks and nonce checks on any potential entry points, though the number of entry points is zero, suggests a lack of robust security measures in place if any were to be introduced in future versions or if the static analysis missed something. The taint analysis showing no flows is a positive sign, but this could be due to a lack of complex data flows or incomplete analysis.
The plugin has a history of known vulnerabilities, with one medium-severity Cross-Site Request Forgery (CSRF) vulnerability currently unpatched. This indicates a recurring pattern of security weaknesses, specifically related to CSRF, and the fact that it remains unpatched is a significant concern. While the plugin demonstrates good practices in SQL query handling, the critical issues with output escaping and the unpatched CSRF vulnerability outweigh these strengths, necessitating caution.
Key Concerns
- Unpatched CVE (Medium Severity)
- Low output escaping percentage
- No capability checks
- No nonce checks
Related Posts Widget with Thumbnails Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Related Posts Widget with Thumbnails <= 1.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Related Posts Widget with Thumbnails Release Timeline
Related Posts Widget with Thumbnails Code Analysis
SQL Query Safety
Output Escaping
Related Posts Widget with Thumbnails Attack Surface
WordPress Hooks 5
Maintenance & Trust
Related Posts Widget with Thumbnails Maintenance & Trust
Maintenance Signals
Community Trust
Related Posts Widget with Thumbnails Alternatives
Random Posts and Pages Widget
ays-random-posts-and-pages
The main advantage of this widget is random movement of random links and every time they are changing.
CP Related Posts
cp-related-posts
CP Related Posts is a plugin that displays related articles on your website, manually, or by the terms in the content, title or abstract, and tags
Related Items
related-items
Related Items plugin lets you relate a page, post or custom post type to other pages, posts and custom post types.
Related Articles by Tag Lite
related-articles-by-tag
With this plugin you can add a list of links to posts having the same tag(s) of the current post.
Duplicate Post
copy-delete-posts
Duplicate post
Related Posts Widget with Thumbnails Developer Profile
15 plugins · 345K total installs
How We Detect Related Posts Widget with Thumbnails
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-css3-related-posts-widget/js/simpletabs_1.3.js/wp-content/plugins/advanced-css3-related-posts-widget/css/simpletabs.css/wp-content/plugins/advanced-css3-related-posts-widget/images/noimage.png/wp-content/plugins/advanced-css3-related-posts-widget/js/simpletabs_1.3.jsHTML / DOM Fingerprints
related-posts-widget