
Advanced Featured Post Widget Security & Risk Analysis
wordpress.org/plugins/advanced-featured-post-widgetWith the Advanced Featured Post Widget you can put a certain post (or post type) in the focus and style it differently.
Is Advanced Featured Post Widget Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Featured Post Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of advanced-featured-post-widget v3.5.2 indicates a generally good security posture in terms of exposed entry points. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected access, which is a significant strength. Furthermore, all detected SQL queries utilize prepared statements, mitigating risks associated with direct SQL injection through database interactions.
However, the analysis also reveals several areas of concern. The presence of the `create_function` dangerous function is a red flag, as it can be a vector for code injection if user input is ever indirectly passed to it, though no taint flows were found to exploit this directly. A significant weakness lies in the output escaping, with only 32% of outputs being properly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site's content, especially when user-controlled data is displayed without adequate sanitization. The taint analysis, while showing no critical or high severity flows, did reveal two flows with unsanitized paths, which could potentially lead to directory traversal or other file system related attacks if these paths are influenced by user input.
The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator, suggesting a track record of security maturity. However, the absence of past vulnerabilities should not lead to complacency, especially given the identified code signals like insufficient output escaping and the use of dangerous functions. The overall risk is moderate, leaning towards concerning due to the significant XSS potential stemming from poor output escaping and the presence of a dangerous function without clear sanitization paths for user input. The lack of capability checks and nonce checks on potential, albeit currently non-existent, entry points is also a weakness if new entry points are introduced in the future.
Key Concerns
- Insufficient output escaping (32%)
- Presence of dangerous function (create_function)
- Unsanitized paths in taint flows (2)
- No nonce checks
- No capability checks
Advanced Featured Post Widget Security Vulnerabilities
Advanced Featured Post Widget Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Advanced Featured Post Widget Attack Surface
WordPress Hooks 14
Maintenance & Trust
Advanced Featured Post Widget Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Featured Post Widget Alternatives
Featured Post Widget
post-feature-widget
With the Featured Post Widget you can put a certain post in the focus and style it differently.
Feature A Page Widget
feature-a-page-widget
A widget to display an attractive summary of any page in any widget area.
YD Featured Box Widget
yd-featured-block-widget
Quick and simple featured boxes as widgets
Widgets on Pages
widgets-on-pages
The easiest and highest rated way to Add Widgets or Sidebars to Posts and Pages using Visual editor, shortcodes or template tags.
Advanced Random Posts Widget
advanced-random-posts-widget
Provides flexible and advanced random posts. Display it via shortcode or widget with thumbnails, post excerpt, and much more!
Advanced Featured Post Widget Developer Profile
8 plugins · 3K total installs
How We Detect Advanced Featured Post Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-featured-post-widget/ta-expander.js/wp-content/plugins/advanced-featured-post-widget/ta-expander.min.js/wp-content/plugins/advanced-featured-post-widget/ta-expander.js/wp-content/plugins/advanced-featured-post-widget/ta-expander.min.jsadvanced-featured-post-widget/ta-expander.js?ver=advanced-featured-post-widget/ta-expander.min.js?ver=HTML / DOM Fingerprints
data-advanced-fpw-post-iddata-advanced-fpw-post-titledata-advanced-fpw-post-excerptdata-advanced-fpw-post-thumbnaildata-advanced-fpw-post-linktaExpander[advanced_featured_post][advanced_featured_post_widget]