Akl Webhost Post Widget Security & Risk Analysis

wordpress.org/plugins/akl-webhost-post-widget

This plugin enables you to edit and display posts in your sidebar. You just need to set the options.

0 active installs v1.0 PHP + WP 3.1+ Updated Aug 22, 2017
best-pluginsbest-postscommentspostssidebar-posts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Akl Webhost Post Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Akl Webhost Post Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin "akl-webhost-post-widget" v1.0 exhibits a generally positive security posture based on the provided static analysis. The complete absence of detected dangerous functions, SQL queries executed solely via prepared statements, no file operations, and no external HTTP requests are strong indicators of secure coding practices. Furthermore, the lack of any recorded vulnerabilities or CVEs historically suggests a well-maintained and secure plugin.

However, several areas raise significant concerns. The total absence of entry points like AJAX handlers, REST API routes, shortcodes, or cron events is unusual and could indicate an incomplete plugin or a misleading analysis. More critically, the extremely low percentage of properly escaped output (11%) represents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce checks and capability checks across any potential entry points further exacerbates this risk, as any user input, even if indirectly processed, could be injected into the output.

While the plugin's history is clean, the code analysis reveals a significant weakness in output sanitization. The lack of any detected taint flows is likely a direct consequence of the minimal attack surface and the absence of complex logic, but the poor output escaping means that any user-supplied data that *does* get processed is at high risk of being exploited to inject malicious scripts.

Key Concerns

  • Low output escaping percentage
  • No nonce checks
  • No capability checks
  • Unusual lack of entry points
Vulnerabilities
None known

Akl Webhost Post Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Akl Webhost Post Widget Release Timeline

v4.8.1
Code Analysis
Analyzed Apr 16, 2026

Akl Webhost Post Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
25
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

11% escaped28 total outputs
Attack Surface

Akl Webhost Post Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initAkl_Post_Widget.php:196
Maintenance & Trust

Akl Webhost Post Widget Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedAug 22, 2017
PHP min version
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Akl Webhost Post Widget Developer Profile

Usama Khalid

3 plugins · 100 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Akl Webhost Post Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/akl-webhost-post-widget/assets/question_mark.png

HTML / DOM Fingerprints

CSS Classes
widgettitlewidget-wrap
HTML Comments
this is the post heading value setter...........this is the end post heading value setter...........this is field which is used to select image.........this is end of field which is used to select image.........+2 more
Data Attributes
akl_post_widgetakl_post_widget_input_valueakl_post_widget_image_urlakl_post_widget_posts
FAQ

Frequently Asked Questions about Akl Webhost Post Widget