
Contextual Related Posts Security & Risk Analysis
wordpress.org/plugins/contextual-related-postsKeep visitors on your site longer with intelligent, fast-loading, contextually related posts. Block, shortcode, custom post type and widget ready.
Is Contextual Related Posts Safe to Use in 2026?
Generally Safe
Score 89/100Contextual Related Posts has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin exhibits several positive security practices, including a high percentage of prepared SQL statements and properly escaped output, which are crucial for preventing common web vulnerabilities. The static analysis also shows a minimal attack surface with no unprotected entry points identified in the analyzed components. The absence of critical or high-severity taint analysis findings further suggests that core code flows are likely well-sanitized.
However, the plugin's vulnerability history is a significant concern. With 7 known CVEs, including a past critical and a high-severity vulnerability, and a recent critical vulnerability discovered on May 7, 2025, there's a clear pattern of exploitable weaknesses. The common types of vulnerabilities (XSS, missing authorization, CSRF, SQL injection) indicate a recurring struggle with secure input handling and access control. The presence of a bundled library (Freemius v1.0) also warrants attention, as outdated bundled components can introduce indirect vulnerabilities.
Overall, while the current version's static analysis reveals good fundamental security practices, the historical prevalence of significant vulnerabilities, particularly recent ones, indicates a need for ongoing vigilance and thorough security reviews. Users should prioritize keeping the plugin updated to the latest patched version to mitigate past risks.
Key Concerns
- History of 7 known CVEs
- Recent critical CVE on 2025-05-07
- Bundled outdated library (Freemius v1.0)
Contextual Related Posts Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
Contextual Related Posts <= 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Contextual Related Posts <= 3.3.1 - Missing Authorization in crp_ajax_clearcache
Contextual Related Posts <= 3.3.1 - Cross-Site Request Forgery in crpClearCache
Contextual Related Posts <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute
Contextual Related Posts <= 2.9.3 - Cross-Site Request Forgery
Contextual Related Posts <= 1.8.6 - Cross-Site Request Forgery to Cross-Site Scripting
Contextual Related Posts < 1.8.10.2 - SQL Injection
Contextual Related Posts Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Contextual Related Posts Attack Surface
Shortcodes 1
WordPress Hooks 41
Maintenance & Trust
Contextual Related Posts Maintenance & Trust
Maintenance Signals
Community Trust
Contextual Related Posts Alternatives
YARPP – Yet Another Related Posts Plugin
yet-another-related-posts-plugin
The best WordPress plugin for displaying related posts. Simple and flexible, with a powerful proven algorithm and inbuilt caching.
Awesome Related Posts – Display Contextual Similar Posts
awesome-related-posts
Displays related posts based on categories, tags, and custom taxonomies with customizable layouts.
Related Posts for WordPress
related-posts-for-wp
The best WordPress plugin for related posts. Simple, flexible, powerful algorithm, and built-in caching. Fully setup with only 1 click!
SPAI – Similar posts AI Plugin
similar-posts-ai-spai
Creates an AI-based recommended articles widget. The fastest plugin, since all calculations take place on the developer's servers.
Super Related Posts – Lightweight, High Performance Algorithm & Increase Traffic!
super-related-posts
Related Posts Plugin to improve Traffic & Bounce-Rate with Superior Algorithm. ZERO Server Load & Highly Configurable Related Post Plugin.
Contextual Related Posts Developer Profile
31 plugins · 89K total installs
How We Detect Contextual Related Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contextual-related-posts/css/crp-admin.css/wp-content/plugins/contextual-related-posts/js/crp-admin.js/wp-content/plugins/contextual-related-posts/js/crp-shortcode-button.js/wp-content/plugins/contextual-related-posts/js/crp-widget.js/wp-content/plugins/contextual-related-posts/css/crp-display.css/wp-content/plugins/contextual-related-posts/js/crp-frontend.js/wp-content/plugins/contextual-related-posts/default.png/wp-content/plugins/contextual-related-posts/js/crp-admin.js/wp-content/plugins/contextual-related-posts/js/crp-shortcode-button.js/wp-content/plugins/contextual-related-posts/js/crp-widget.js/wp-content/plugins/contextual-related-posts/js/crp-frontend.jscontextual-related-posts/css/crp-admin.css?ver=contextual-related-posts/js/crp-admin.js?ver=contextual-related-posts/js/crp-shortcode-button.js?ver=contextual-related-posts/js/crp-widget.js?ver=contextual-related-posts/css/crp-display.css?ver=contextual-related-posts/js/crp-frontend.js?ver=HTML / DOM Fingerprints
crp-widgetcrp-displaycrp_related_posts<!-- Begin Contextual Related Posts --><!-- End Contextual Related Posts -->data-crp-slugdata-crp-postiddata-crp-related-post-idcrp_settingscrp_ajax_url[crp]