anpPopular Post Security & Risk Analysis

wordpress.org/plugins/anppopular-post

Widget to display a list of the most commented posts. The posts are displayed on a color scale of colors.

10 active installs v1.0.6 PHP + WP 3.0+ Updated Unknown
commentmost-commentpopular-postspostswidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is anpPopular Post Safe to Use in 2026?

Generally Safe

Score 100/100

anpPopular Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "anppopular-post" v1.0.6 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a zero attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, with no identified dangerous functions, file operations, or external HTTP requests. The plugin also has no recorded vulnerability history, indicating a lack of past security incidents. However, significant concerns arise from the code signals. All SQL queries (16 in total) are executed without prepared statements, presenting a high risk of SQL injection vulnerabilities. Furthermore, a very low percentage (6%) of output is properly escaped, creating a substantial risk of cross-site scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on any potential entry points, although the analysis shows zero such points, points to a lack of fundamental security mechanisms if the attack surface were to expand in future versions.

Key Concerns

  • SQL queries not using prepared statements
  • Low percentage of properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

anpPopular Post Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

anpPopular Post Code Analysis

Dangerous Functions
0
Raw SQL Queries
16
0 prepared
Unescaped Output
45
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared16 total queries

Output Escaping

6% escaped48 total outputs
Attack Surface

anpPopular Post Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_headanp_popular_post.php:42
actionmanage_posts_custom_columnanp_popular_post.php:43
filtermanage_posts_columnsanp_popular_post.php:44
actionthe_contentanp_popular_post.php:211
actionadmin_print_scripts-widgets.phpanp_popular_post.php:225
actioninitanp_popular_post.php:238
actionwidgets_initanp_popular_post.php:705
actionwp_headanp_popular_post.php:731
Maintenance & Trust

anpPopular Post Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

anpPopular Post Developer Profile

antocara

2 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect anpPopular Post

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/anppopular-post/js/jscolor/jscolor.js/wp-content/plugins/anppopular-post/js/script.js
Script Paths
/wp-content/plugins/anppopular-post/js/jscolor/jscolor.js/wp-content/plugins/anppopular-post/js/script.js

HTML / DOM Fingerprints

CSS Classes
num_post_list
HTML Comments
Copyright 2012 Antonio Carabantes(Email : antocara@gmail.com)This program is free software: you can redistribute it and/or modifyit under the terms of the GNU General Public License as published bythe Free Software Foundation, either version 3 of the License, or+24 more
FAQ

Frequently Asked Questions about anpPopular Post