
Category Posts Widget Security & Risk Analysis
wordpress.org/plugins/category-postsAdds a widget that shows the most recent posts from a single category.
Is Category Posts Widget Safe to Use in 2026?
Generally Safe
Score 99/100Category Posts Widget has a strong security track record. Known vulnerabilities have been patched promptly.
The "category-posts" plugin version 4.9.22 exhibits a generally good security posture based on the provided static analysis. The complete absence of direct attack surface entry points like AJAX handlers, REST API routes, and shortcodes is a significant strength. Furthermore, all identified SQL queries utilize prepared statements, and there are no observed file operations or external HTTP requests, minimizing common web application attack vectors. The plugin also implements capability checks, indicating an awareness of user privilege management. However, a concerning weakness lies in the output escaping, with only 57% of outputs being properly escaped. This leaves a notable portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks, especially if user-supplied data is rendered directly to the page without adequate sanitization. The historical vulnerability data, showing two medium severity CVEs related to XSS and a recent patch in 2025, reinforces the concern around improper output neutralization. While there are no currently unpatched vulnerabilities, the recurring XSS pattern suggests that output handling remains a critical area for improvement.
Key Concerns
- Output escaping is only 57% proper
- Bundled outdated library: TinyMCE v4.7
- Bundled outdated library: Select2 v4.0.3
- Two medium severity CVEs historically
Category Posts Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Category Posts Widget <= 4.9.19 - Authenticated (Admin+) Stored Cross-Site Scripting
Category Posts Widget <= 4.9.17 - Authenticated (Admin+) Stored Cross-Site SCripting
Category Posts Widget Code Analysis
Bundled Libraries
Output Escaping
Category Posts Widget Attack Surface
WordPress Hooks 31
Maintenance & Trust
Category Posts Widget Maintenance & Trust
Maintenance Signals
Community Trust
Category Posts Widget Alternatives
Recent Posts by Category Widget
recent-posts-by-category-widget
Just like the default Recent Posts widget except you can choose a category to pull posts from.
Custom Recent Posts Widget
custom-recent-posts-widget
A widget to show recent posts list based on categories or tags
Custom Recent Posts Widget Plus
custom-recent-posts-widget-plus
Nice widget it is like the default Recent Posts widget except you can choose a category and in addition show the thumbnails.
News In Stack Widget
news-in-stack-widget
Just another recent post widget. Simple but flexible.
Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor)
content-views-query-and-display-post-page
Easy to show posts, pages, custom posts in customizable grid, list, slider, accordion... Available as Widgets (for Elementor), Shortcode, and Blocks.
Category Posts Widget Developer Profile
2 plugins · 40K total installs
How We Detect Category Posts Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/category-posts/styles/admin/category-posts-widget.css/wp-content/plugins/category-posts/js/admin/category-posts-widget.min.js/wp-content/plugins/category-posts/js/admin/category-posts-widget.js/wp-content/plugins/category-posts/js/frontend/category-posts-frontend.min.js/wp-content/plugins/category-posts/js/frontend/category-posts-frontend.jsjs/admin/category-posts-widget.min.jsjs/admin/category-posts-widget.jsjs/frontend/category-posts-frontend.min.jsjs/frontend/category-posts-frontend.jscategory-posts-widget.css?ver=category-posts-widget.min.js?ver=category-posts-widget.js?ver=category-posts-frontend.min.js?ver=category-posts-frontend.js?ver=HTML / DOM Fingerprints
cat-posts-widget<!-- Plugin Name: Category Posts Widget --><!-- Plugin URI: https://wordpress.org/plugins/category-posts/ --><!-- Description: Adds a widget that shows the most recent posts from a single category. --><!-- Author: TipTopPress -->+11 moredata-catposts-noncewindow.tiptoppresstiptoppress.accordiontiptoppress.template_tagstiptoppress.categoryPostswindow.cwp_default_thumb_selection[catposts