
Display Last Post(s) Security & Risk Analysis
wordpress.org/plugins/display-last-postsAllows to display the last post(s) anywhere on your WordPress site/blog, using a shortcode or a short PHP code (for the templates).
Is Display Last Post(s) Safe to Use in 2026?
Generally Safe
Score 85/100Display Last Post(s) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "display-last-posts" v1.0 plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. The plugin has a minimal attack surface, with only one shortcode identified as an entry point, and no AJAX handlers or REST API routes that are exposed without authentication checks. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and known vulnerabilities in its history are positive indicators. However, a significant concern arises from the lack of output escaping. With 100% of outputs not being properly escaped, this presents a substantial risk for Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site. The absence of nonce and capability checks also contributes to potential security weaknesses, as these are crucial for preventing Cross-Site Request Forgery (CSRF) and unauthorized actions. While the plugin uses prepared statements for its SQL queries, the unescaped output remains the most critical issue identified.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
Display Last Post(s) Security Vulnerabilities
Display Last Post(s) Code Analysis
Output Escaping
Display Last Post(s) Attack Surface
Shortcodes 1
Maintenance & Trust
Display Last Post(s) Maintenance & Trust
Maintenance Signals
Community Trust
Display Last Post(s) Alternatives
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
Posts in Page
posts-in-page
Easily add one or more posts to any page using simple shortcodes.
azurecurve Flags
azurecurve-flags
Allows a 16x16 flag to be displayed in a post or page using a shortcode.
WP Multilingual Sitemap
wp-multilingual-sitemap
Allows creating complete multilingual sitemaps of your entire blog.
Template Tag Shortcodes
template-tag-shortcodes
A plugin that turns many of the WP template tags into shortcodes (40+ shortcodes).
Display Last Post(s) Developer Profile
1 plugin · 80 total installs
How We Detect Display Last Post(s)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
display-last-posts<h3><a href=""></a></h3><div class="display-last-posts">