
BNS Featured Tag Security & Risk Analysis
wordpress.org/plugins/bns-featured-tagDisplays most recent posts from a specific featured tag or tags.
Is BNS Featured Tag Safe to Use in 2026?
Generally Safe
Score 85/100BNS Featured Tag has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bns-featured-tag" plugin v2.7.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no known vulnerabilities (CVEs). The attack surface is also commendably small, with only one shortcode entry point and no unprotected AJAX handlers or REST API routes. Furthermore, the absence of file operations and external HTTP requests reduces potential vectors for compromise. However, significant concerns arise from the output escaping. With 94 outputs and only 1% properly escaped, there is a high probability of Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is reflected without proper sanitization. The lack of nonce checks and capability checks on the identified shortcode also presents a potential risk, as it implies that the shortcode's functionality might be executed by unauthenticated or unauthorized users, further exacerbating the XSS risk if not handled with extreme care. The taint analysis showing zero flows might be due to the limited scope or complexity of the analyzed code, but coupled with the output escaping issue, it doesn't negate the inherent risk.
Key Concerns
- Insufficient output escaping (99% unescaped)
- Missing nonce checks on entry points
- Missing capability checks on entry points
BNS Featured Tag Security Vulnerabilities
BNS Featured Tag Code Analysis
Output Escaping
BNS Featured Tag Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
BNS Featured Tag Maintenance & Trust
Maintenance Signals
Community Trust
BNS Featured Tag Alternatives
Featured Post Type
featured-post-type-widget
Displays most recent posts from a specific post type and a drop down to select previous entries.
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
Flexible Posts Widget
flexible-posts-widget
An advanced posts display widget with many options. Display posts in your sidebars any way you'd like!
BNS Featured Tag Developer Profile
18 plugins · 2K total installs
How We Detect BNS Featured Tag
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bns-featured-tag/bnsft-style.css/wp-content/plugins/bns-featured-tag/bnsft-custom-style.cssbns-featured-tag/bnsft-style.css?ver=bns-featured-tag/bnsft-custom-style.css?ver=HTML / DOM Fingerprints
bns-featured-tagbnsft-linkid_base: 'bns-featured-tag'