
BCD Upcoming Posts Security & Risk Analysis
wordpress.org/plugins/bcd-upcoming-postsDisplays a list of upcoming posts in a widget.
Is BCD Upcoming Posts Safe to Use in 2026?
Generally Safe
Score 85/100BCD Upcoming Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bcd-upcoming-posts" plugin v1.4.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query handling, utilizing prepared statements exclusively, and shows no history of recorded vulnerabilities, suggesting a potentially stable and secure codebase over time. The attack surface appears minimal, with only one shortcode and no AJAX handlers or REST API routes without authentication checks. There are also no file operations or external HTTP requests.
However, significant security concerns are present. The use of the `create_function` is a critical red flag, as it can be exploited for code injection if any user-supplied data indirectly influences its execution. Furthermore, a complete lack of output escaping across all identified outputs is a major vulnerability, exposing the plugin to Cross-Site Scripting (XSS) attacks. The absence of nonce checks and capability checks on the single entry point (shortcode) further exacerbates the risk of unauthorized actions or unintended behavior. While no taint flows were detected in this static analysis, the presence of `create_function` and unescaped output suggests a high likelihood of exploitable vulnerabilities.
In conclusion, while the plugin's history and SQL handling are positive indicators, the identified code signals, particularly `create_function` and the universal lack of output escaping, present substantial security risks. These weaknesses significantly outweigh the strengths, leading to a concerning security posture that requires immediate attention. The minimal attack surface is negated by the critical vulnerabilities within that surface.
Key Concerns
- Use of dangerous create_function
- 0% output escaping
- 0 nonce checks on entry points
- 0 capability checks on entry points
BCD Upcoming Posts Security Vulnerabilities
BCD Upcoming Posts Code Analysis
Dangerous Functions Found
Output Escaping
BCD Upcoming Posts Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
BCD Upcoming Posts Maintenance & Trust
Maintenance Signals
Community Trust
BCD Upcoming Posts Alternatives
SOUP – Show off Upcoming Posts
soup-show-off-upcoming-posts
Displays your upcoming posts in a sidebar widget to tease your readers
Linked Future Posts Widget
linked-future-posts-widget
A widget that displays a list of scheduled posts with links to the posts.
Blog Post Calendar Widget
blog-post-calendar-widget
The Blog Posts Calendar Widget allows you to display your archived or future posts in a calendar as a sidebar widget.
Scheduled Posts Showcase
scheduled-posts-showcase
Display your scheduled and future posts on the frontend without generating 404 links. Show visitors what's coming next.
Elementor Custom Skin
ele-custom-skin
Create new skins for Elementor PRO 3.x page builder. Design your own skins for Post and Post Archive Widgets using Elementor Loop Templates.
BCD Upcoming Posts Developer Profile
2 plugins · 20 total installs
How We Detect BCD Upcoming Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bcd-upcoming-posts/scripts/bcdup-script.js/wp-content/plugins/bcd-upcoming-posts/css/bcdup-css.cssscripts/bcdup-script.jsbcd-upcoming-posts/scripts/bcdup-script.js?ver=bcd-upcoming-posts/css/bcdup-css.css?ver=HTML / DOM Fingerprints
BCD_Upcoming_Postsdata-bcd-upcoming-postsbcdup_script