
Custom Related Posts Security & Risk Analysis
wordpress.org/plugins/custom-related-postsManual related posts without slowing down your website!
Is Custom Related Posts Safe to Use in 2026?
Generally Safe
Score 96/100Custom Related Posts has a strong security track record. Known vulnerabilities have been patched promptly.
The "custom-related-posts" plugin v1.8.1 exhibits a mixed security posture. While it demonstrates several good security practices such as a substantial number of nonce and capability checks, and a moderate use of prepared statements for SQL queries, there are notable areas of concern. The presence of one REST API route without permission callbacks presents a direct attack vector that could be exploited by unauthenticated users. Furthermore, the taint analysis reveals two flows with unsanitized paths, both categorized as high severity, indicating potential vulnerabilities in how user-supplied data is handled, which could lead to code execution or information disclosure.
Key Concerns
- REST API route without permission callbacks
- High severity taint flow with unsanitized paths (2 instances)
- Output escaping is only 48% properly escaped
- Bundled library (TinyMCE) may have unpatched vulnerabilities
Custom Related Posts Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Custom Related Posts <= 1.8.0 - Unauthenticated Information Exposure
Custom Related Posts <= 1.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Custom Related Posts <= 1.7.3 - Missing Authorization to Authenticated (Subscriber+) Private Post Search and Relation Updates
Custom Related Posts Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Custom Related Posts Attack Surface
AJAX Handlers 5
REST API Routes 5
Shortcodes 1
WordPress Hooks 24
Maintenance & Trust
Custom Related Posts Maintenance & Trust
Maintenance Signals
Community Trust
Custom Related Posts Alternatives
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Custom Post Type Widgets
custom-post-type-widgets
Custom Post Type Widgets plugin adds default custom post type widgets.
Social LikeBox & Feed
facebook-by-weblizar
Display your FaceBook Feed and Like box on your website with this outstanding plugin. It is completely customizable, responsive and the code is search …
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
Same Category Posts
same-category-posts
Show posts related to the current category or other custom post types.
Custom Related Posts Developer Profile
6 plugins · 79K total installs
How We Detect Custom Related Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-related-posts/dist/public.css/wp-content/plugins/custom-related-posts/dist/admin.css/wp-content/plugins/custom-related-posts/dist/admin.js/wp-content/plugins/custom-related-posts/dist/admin.jscustom-related-posts/dist/public.css?ver=custom-related-posts/dist/admin.css?ver=custom-related-posts/dist/admin.js?ver=HTML / DOM Fingerprints
crp_remove_relationcrp_remove_relation_tocrp_remove_relation_bothcrp_remove_relationcrp_remove_relation_tocrp_remove_relation_bothcrp_admin/wp-json/custom-related-posts/v1/related