
ARK Related Posts Security & Risk Analysis
wordpress.org/plugins/ark-relatedpostПлагин выводит связанные записи к постам с миниатюрами этих записей.
Is ARK Related Posts Safe to Use in 2026?
Generally Safe
Score 99/100ARK Related Posts has a strong security track record. Known vulnerabilities have been patched promptly.
The "ark-relatedpost" plugin version 2.20 exhibits a generally good security posture based on the static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength. Furthermore, the code demonstrates strong adherence to secure coding practices with 100% of SQL queries utilizing prepared statements and a very high percentage (97%) of outputs being properly escaped. The presence of a nonce check is also a positive indicator. However, the vulnerability history, while currently showing no unpatched issues, reveals a past CVE, specifically a medium-severity Cross-Site Request Forgery (CSRF) vulnerability. This history, combined with a complete lack of capability checks in the analyzed code, suggests a potential for overlooked authorization vulnerabilities if the plugin were to gain more complex functionalities or interact with sensitive data.
While the static analysis reveals an extremely small attack surface and good handling of common vulnerabilities like SQL injection and XSS, the historical data points to a past susceptibility to CSRF. The absence of capability checks in the analyzed code, despite the presence of a nonce check, is a weakness that could be exploited if the plugin's features were to expand or if it were to handle user-specific data. The zero taint flows are excellent, indicating no easily discoverable data corruption or leakage paths. Overall, the plugin is relatively secure for its current functionalities, but the historical vulnerability and lack of capability checks warrant caution and suggest that future development should prioritize robust authorization mechanisms.
Key Concerns
- Past medium CVE (CSRF)
- No capability checks found
- Minor unescaped output (3%)
ARK Related Posts Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ARK Related Posts <= 2.19 - Cross-Site Request Forgery to Settings Update
ARK Related Posts Code Analysis
Output Escaping
ARK Related Posts Attack Surface
WordPress Hooks 4
Maintenance & Trust
ARK Related Posts Maintenance & Trust
Maintenance Signals
Community Trust
ARK Related Posts Alternatives
Inline Related Posts
intelly-related-posts
Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
YARPP – Yet Another Related Posts Plugin
yet-another-related-posts-plugin
The best WordPress plugin for displaying related posts. Simple and flexible, with a powerful proven algorithm and inbuilt caching.
Contextual Related Posts
contextual-related-posts
Keep visitors on your site longer with intelligent, fast-loading, contextually related posts. Block, shortcode, custom post type and widget ready.
Related Posts for WordPress
related-posts-for-wp
The best WordPress plugin for related posts. Simple, flexible, powerful algorithm, and built-in caching. Fully setup with only 1 click!
ARK Related Posts Developer Profile
2 plugins · 400 total installs
How We Detect ARK Related Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ark-relatedpost/js/plugin-script.js/wp-content/plugins/ark-relatedpost/js/plugin-script.jsHTML / DOM Fingerprints
name="ark_imgsize"name="ark_imgurl"name="ark_maxword"name="ark_bgcolor"name="ark_nobgcolor"name="ark_bordercolor"+28 moreplugins_url