Arewa Recently Viewed Content Security & Risk Analysis

wordpress.org/plugins/arewa-recently-viewed-content

Track and display recently viewed content for both logged-in and guest users with automatic history sync and multiple layout options.

0 active installs v2.0.6 PHP 7.4+ WP 5.8+ Updated Feb 27, 2026
recently-viewed-postsrecently-viewed-productsrecently-vieweduser-historywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Arewa Recently Viewed Content Safe to Use in 2026?

Generally Safe

Score 100/100

Arewa Recently Viewed Content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'arewa-recently-viewed-content' v2.0.6 plugin exhibits a strong security posture based on the provided static analysis. It successfully employs prepared statements for all SQL queries, demonstrates robust output escaping with 94% of outputs properly escaped, and incorporates numerous nonce and capability checks across its entry points. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. The plugin also has a clean vulnerability history, with no recorded CVEs, indicating a history of secure development and maintenance.

While the static analysis reveals no critical or high severity issues in taint flows and a protected attack surface, the 94% output escaping rate suggests a small percentage of outputs might be vulnerable to Cross-Site Scripting (XSS) if the remaining 6% are not handled correctly. However, without specific examples of unsanitized outputs, this remains a theoretical concern. The lack of taint analysis data is unusual but doesn't inherently point to a weakness; it might simply mean no flows were detected or the analysis tool did not execute fully for this specific analysis.

Overall, the plugin appears to be developed with security in mind, adhering to many best practices. The minimal identified weaknesses are mostly in areas that typically require deeper manual code review to confirm exploitation potential. The clean vulnerability history is a significant positive indicator. Given the available data, the plugin presents a low risk to WordPress installations.

Key Concerns

  • Output escaping is not 100%
Vulnerabilities
None known

Arewa Recently Viewed Content Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Arewa Recently Viewed Content Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
18
262 escaped
Nonce Checks
9
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

94% escaped280 total outputs
Attack Surface

Arewa Recently Viewed Content Attack Surface

Entry Points9
Unprotected0

AJAX Handlers 8

authwp_ajax_arwrev_remove_itemincludes\class-arwrev-ajax.php:52
authwp_ajax_arwrev_clear_allincludes\class-arwrev-ajax.php:53
authwp_ajax_arwrev_export_dataincludes\class-arwrev-ajax.php:54
authwp_ajax_arwrev_import_dataincludes\class-arwrev-ajax.php:55
noprivwp_ajax_arwrev_track_guest_viewincludes\class-arwrev-ajax.php:58
authwp_ajax_arwrev_track_guest_viewincludes\class-arwrev-ajax.php:59
noprivwp_ajax_arwrev_guest_remove_itemincludes\class-arwrev-ajax.php:62
noprivwp_ajax_arwrev_guest_clear_allincludes\class-arwrev-ajax.php:65

Shortcodes 1

[watch_history] includes\class-arwrev-shortcode-new.php:62
WordPress Hooks 23
actioninitarewa-recently-viewed-content.php:106
actionafter_setup_themearewa-recently-viewed-content.php:115
actionwp_enqueue_scriptsarewa-recently-viewed-content.php:118
actionadmin_enqueue_scriptsarewa-recently-viewed-content.php:119
actionarwrev_enqueue_assetsarewa-recently-viewed-content.php:121
actioninitarewa-recently-viewed-content.php:190
filterquery_varsarewa-recently-viewed-content.php:193
actionplugins_loadedarewa-recently-viewed-content.php:390
actionplugins_loadedarewa-recently-viewed-content.php:400
actionplugins_loadedarewa-recently-viewed-content.php:403
actionadmin_noticesarewa-recently-viewed-content.php:563
actionadmin_noticesarewa-recently-viewed-content.php:587
actionadmin_initarewa-recently-viewed-content.php:614
actioninitincludes\class-arwrev-admin-settings-tabbed.php:47
actionadmin_initincludes\class-arwrev-admin-settings-tabbed.php:48
actionadmin_menuincludes\class-arwrev-admin-settings-tabbed.php:55
actionadmin_initincludes\class-arwrev-data-manager.php:48
actioninitincludes\class-arwrev-shortcode-new.php:53
actionwp_enqueue_scriptsincludes\class-arwrev-shortcode-new.php:55
actiontemplate_redirectincludes\class-arwrev-tracker.php:52
actionarwrev_cleanupincludes\class-arwrev-tracker.php:53
actionwp_loginincludes\class-arwrev-tracker.php:54
actionadmin_noticesuninstall.php:118

Scheduled Events 1

arwrev_cleanup
Maintenance & Trust

Arewa Recently Viewed Content Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 27, 2026
PHP min version7.4
Downloads211

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Arewa Recently Viewed Content Developer Profile

arewadev

3 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Arewa Recently Viewed Content

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/arewa-recently-viewed-content/assets/css/frontend.css/wp-content/plugins/arewa-recently-viewed-content/assets/js/frontend.js
Script Paths
/wp-content/plugins/arewa-recently-viewed-content/assets/js/frontend.js
Version Parameters
arewa-recently-viewed-content/assets/css/frontend.css?ver=arewa-recently-viewed-content/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
arwrev-recently-viewed-contentarwrev-layout-gridarwrev-layout-listarwrev-layout-carousel
HTML Comments
<!-- Start ARWREV Recently Viewed Content --><!-- End ARWREV Recently Viewed Content -->
Data Attributes
data-post-iddata-post-type
JS Globals
arwrev
Shortcode Output
[arewa_recently_viewed_content[arwrev_recently_viewed_content
FAQ

Frequently Asked Questions about Arewa Recently Viewed Content