
Advanced Related Posts Security & Risk Analysis
wordpress.org/plugins/advanced-related-postsThis plugin allows you to display related posts with widget or under the post with advanced options.
Is Advanced Related Posts Safe to Use in 2026?
Generally Safe
Score 99/100Advanced Related Posts has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The advanced-related-posts plugin version 1.9.2 exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices by largely utilizing prepared statements for SQL queries and including nonce checks and capability checks, the presence of 6 AJAX handlers without any authentication or permission checks presents a substantial attack surface. This means that any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure.
Taint analysis revealed one flow with unsanitized paths, which, while not classified as critical or high severity, still indicates a potential area for concern regarding how user-supplied data is handled. The plugin's lack of known historical vulnerabilities is a positive indicator of past security diligence, but it doesn't negate the risks identified in the current static analysis. The use of the Select2 library, while not inherently problematic, is worth noting as bundled libraries can sometimes introduce vulnerabilities if not kept up-to-date.
In conclusion, the plugin has strengths in its SQL handling and verification mechanisms. However, the primary weakness is the exposed AJAX endpoints. Addressing these unprotected AJAX handlers should be the immediate priority to significantly improve the plugin's security. The presence of an unsanitized path flow, even at a lower severity, warrants further investigation.
Key Concerns
- Unprotected AJAX handlers
- Flow with unsanitized paths
- Low percentage of properly escaped output
Advanced Related Posts Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Advanced Related Posts <= 1.9.1 - Missing Authorization
Advanced Related Posts Release Timeline
Advanced Related Posts Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Advanced Related Posts Attack Surface
AJAX Handlers 6
WordPress Hooks 22
Maintenance & Trust
Advanced Related Posts Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Related Posts Alternatives
Inline Related Posts
intelly-related-posts
Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
YARPP – Yet Another Related Posts Plugin
yet-another-related-posts-plugin
The best WordPress plugin for displaying related posts. Simple and flexible, with a powerful proven algorithm and inbuilt caching.
Contextual Related Posts
contextual-related-posts
Keep visitors on your site longer with intelligent, fast-loading, contextually related posts. Block, shortcode, custom post type and widget ready.
Related Posts for WordPress
related-posts-for-wp
The best WordPress plugin for related posts. Simple, flexible, powerful algorithm, and built-in caching. Fully setup with only 1 click!
Internal Linking of Related Contents
internal-linking-of-related-contents
Internal Linking of Related Contents allows you to automatically insert inline related posts within your WordPress articles.
Advanced Related Posts Developer Profile
18 plugins · 111K total installs
How We Detect Advanced Related Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-related-posts/admin/css/admin-style.css/wp-content/plugins/advanced-related-posts/public/css/public-style.css/wp-content/plugins/advanced-related-posts/admin/js/admin-script.js/wp-content/plugins/advanced-related-posts/public/js/public-script.js/wp-content/plugins/advanced-related-posts/admin/images/icons/icon-arp-128x128.png/wp-content/plugins/advanced-related-posts/admin/images/icons/lightning-white.svg/wp-content/plugins/advanced-related-posts/admin/js/admin-script.js/wp-content/plugins/advanced-related-posts/public/js/public-script.jsadvanced-related-posts/admin/css/admin-style.css?ver=advanced-related-posts/public/css/public-style.css?ver=advanced-related-posts/admin/js/admin-script.js?ver=advanced-related-posts/public/js/public-script.js?ver=HTML / DOM Fingerprints
ays-notice-bannernavigation-barays-arp-logo-container-upgradelogo-containerays-arp-upgrade-containerays-arp-upgrade-to-proays-arp-logo-container-one-time-textmodile-ddmenu-lg+4 moredata-aysarp-post-iddata-aysarp-widget-iddata-aysarp-current-post-iddata-aysarp-taxonomydata-aysarp-titledata-aysarp-show-image+23 moreadvanced_related_posts_obj[related_posts_by_category][related_posts_by_tag][related_posts_by_posts]