
Display Popular Post Security & Risk Analysis
wordpress.org/plugins/display-popular-postDisplay popular post using shortcode ['cb-dp-post']
Is Display Popular Post Safe to Use in 2026?
Generally Safe
Score 85/100Display Popular Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "display-popular-post" v1.0 plugin exhibits a mixed security posture. On the positive side, the static analysis shows no dangerous functions, all SQL queries utilize prepared statements, and there are no recorded vulnerabilities in its history. This suggests a developer who is mindful of common security pitfalls like direct SQL manipulation and known exploits. However, the lack of output escaping on all identified outputs is a significant concern. This creates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-provided data is directly rendered on the page without proper sanitization. Furthermore, the absence of nonce checks and capability checks across its entry points, although currently limited to a single shortcode, indicates a lack of robust access control mechanisms. While the attack surface is small and there are no immediately apparent critical taint flows, the unescaped output and missing authorization checks are weaknesses that could be exploited.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
Display Popular Post Security Vulnerabilities
Display Popular Post Code Analysis
Output Escaping
Display Popular Post Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Display Popular Post Maintenance & Trust
Maintenance Signals
Community Trust
Display Popular Post Alternatives
CB News Ticker
cb-news-ticker
Display News ticker [cb-news-ticker]
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Display Category Posts Via Shortcode Lite
display-category-posts-via-shortcode-lite
Displays posts with their featured images from a specified category in a responsive grid using a simple shortcode. After installation simply go to Se …
Fancy Posts Widget
fancy-posts-widget
Another posts widget plugin
Easy Timeline
easy-timeline
Add a timeline to your website using a simple shortcode.
Display Popular Post Developer Profile
33 plugins · 1K total installs
How We Detect Display Popular Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/display-popular-post/css/style.cssdisplay-popular-post/css/style.css?ver=HTML / DOM Fingerprints
cb-display-popular-post-areacb-single-display-popular-postcb-display-popular-titlecb-display-popular-thumbnilcb-display-popular-contentcb single display popular post startcb single display popular post End<div class="cb-display-popular-post-area"><div class="cb-single-display-popular-post"><div class="cb-display-popular-title"><h2><a href=