
EFavourite Posts Security & Risk Analysis
wordpress.org/plugins/efavourite-postsDo you want to allow your users to add Most Favorite Posts in WordPress Website?
Is EFavourite Posts Safe to Use in 2026?
Generally Safe
Score 85/100EFavourite Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "efavourite-posts" v1.2 plugin exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, file operations, and external HTTP requests is a positive indicator. Crucially, all detected SQL queries are properly prepared, and the presence of nonce and capability checks demonstrates an awareness of basic WordPress security principles. The plugin also boasts a small attack surface with no unprotected entry points identified.
However, the taint analysis reveals two flows with unsanitized paths. While these are not classified as critical or high severity, they represent potential vectors for attackers to inject malicious code or data. The output escaping, while at 76%, indicates that a portion of the output is not being properly sanitized, which could lead to Cross-Site Scripting (XSS) vulnerabilities. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign but doesn't guarantee future security.
Overall, "efavourite-posts" v1.2 is a relatively secure plugin, with its strengths lying in its prepared SQL statements and authentication checks. The primary areas for improvement and concern are the identified unsanitized paths in the taint analysis and the incomplete output escaping, which require attention to mitigate potential security risks.
Key Concerns
- Unsanitized paths found in taint analysis
- Output escaping is not 100%
EFavourite Posts Security Vulnerabilities
EFavourite Posts Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
EFavourite Posts Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
EFavourite Posts Maintenance & Trust
Maintenance Signals
Community Trust
EFavourite Posts Alternatives
WP My Favourites
wp-my-favourites
Choose your favourite posts, pages, comments, media and reorder them to display anywhere on your website.
Heroic Favicon Generator
favhero-favicon-generator
Heroic Favicon Generator is your one-click favicon generator for WordPress.
Simple Woocommerce Favourites
simple-woocommerce-favourites
Manages a simple list of favourites for each user of their preferred products and displays it with a shortcode
WP Favorite Posts Extended
wp-favorite-posts-extended
wp-favorite-posts, reading list, post list, post lists, lists Requires at least: 3.5 Tested up to: 4.0 Stable tag: 0.1 Based on plugin "WP Favor …
Techvoot Favourites for WooCommerce
techvoot-favourites-for-woocommerce
Lets WooCommerce customers save products as Favourites for quick reordering, with admin tools to manage each user's saved products.
EFavourite Posts Developer Profile
4 plugins · 60 total installs
How We Detect EFavourite Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/efavourite-posts/css/efav-style.css/wp-content/plugins/efavourite-posts/js/efav_script.js/wp-content/plugins/efavourite-posts/js/efav_script.jsefavourite-posts/css/efav-style.css?ver=efavourite-posts/js/efav_script.js?ver=HTML / DOM Fingerprints
efav-spanefav-linkefav_actionefav_postidefav_mode