
Advanced Featured Post Widget Security & Risk Analysis
wordpress.org/plugins/advanced-featured-post-widgetWith the Advanced Featured Post Widget you can put a certain post (or post type) in the focus and style it differently.
Is Advanced Featured Post Widget Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Featured Post Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of advanced-featured-post-widget v3.5.2 indicates a generally good security posture in terms of exposed entry points. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected access, which is a significant strength. Furthermore, all detected SQL queries utilize prepared statements, mitigating risks associated with direct SQL injection through database interactions.
However, the analysis also reveals several areas of concern. The presence of the `create_function` dangerous function is a red flag, as it can be a vector for code injection if user input is ever indirectly passed to it, though no taint flows were found to exploit this directly. A significant weakness lies in the output escaping, with only 32% of outputs being properly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site's content, especially when user-controlled data is displayed without adequate sanitization. The taint analysis, while showing no critical or high severity flows, did reveal two flows with unsanitized paths, which could potentially lead to directory traversal or other file system related attacks if these paths are influenced by user input.
The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator, suggesting a track record of security maturity. However, the absence of past vulnerabilities should not lead to complacency, especially given the identified code signals like insufficient output escaping and the use of dangerous functions. The overall risk is moderate, leaning towards concerning due to the significant XSS potential stemming from poor output escaping and the presence of a dangerous function without clear sanitization paths for user input. The lack of capability checks and nonce checks on potential, albeit currently non-existent, entry points is also a weakness if new entry points are introduced in the future.
Key Concerns
- Insufficient output escaping (32%)
- Presence of dangerous function (create_function)
- Unsanitized paths in taint flows (2)
- No nonce checks
- No capability checks
Advanced Featured Post Widget Security Vulnerabilities
Advanced Featured Post Widget Release Timeline
Advanced Featured Post Widget Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Advanced Featured Post Widget Attack Surface
WordPress Hooks 14
Maintenance & Trust
Advanced Featured Post Widget Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Featured Post Widget Alternatives
Featured Post Widget
post-feature-widget
With the Featured Post Widget you can put a certain post in the focus and style it differently.
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Feature A Page Widget
feature-a-page-widget
A widget to display an attractive summary of any page in any widget area.
A5 Recent Post Widget
a5-recent-posts
With the A5 Recent Post Widget you can put your latest post in the focus and style it differently.
YD Featured Box Widget
yd-featured-block-widget
Quick and simple featured boxes as widgets
Advanced Featured Post Widget Developer Profile
11 plugins · 3K total installs
How We Detect Advanced Featured Post Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-featured-post-widget/ta-expander.js/wp-content/plugins/advanced-featured-post-widget/ta-expander.min.js/wp-content/plugins/advanced-featured-post-widget/ta-expander.js/wp-content/plugins/advanced-featured-post-widget/ta-expander.min.jsadvanced-featured-post-widget/ta-expander.js?ver=advanced-featured-post-widget/ta-expander.min.js?ver=HTML / DOM Fingerprints
data-advanced-fpw-post-iddata-advanced-fpw-post-titledata-advanced-fpw-post-excerptdata-advanced-fpw-post-thumbnaildata-advanced-fpw-post-linktaExpander[advanced_featured_post][advanced_featured_post_widget]