
Enhanced Recent Posts Security & Risk Analysis
wordpress.org/plugins/enhanced-recent-postsEnhance the built-in "Recent Posts" widget.
Is Enhanced Recent Posts Safe to Use in 2026?
Generally Safe
Score 85/100Enhanced Recent Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "enhanced-recent-posts" plugin v1.3.4 exhibits a generally positive security posture based on the static analysis. The complete absence of identified dangerous functions, SQL injection vulnerabilities (as all queries use prepared statements), and file operations is commendable. Furthermore, the lack of any known CVEs or historical vulnerabilities suggests a history of secure development or effective patching. However, a significant concern arises from the extremely low percentage of properly escaped output (3%). With 37 outputs identified and only 3% properly escaped, this indicates a high likelihood of cross-site scripting (XSS) vulnerabilities. The plugin also lacks nonce and capability checks on its entry points, which, although currently zero, could become a significant risk if any new entry points are introduced in future versions without proper authorization mechanisms. The overall assessment is that while the plugin avoids common and severe vulnerabilities like SQL injection, its deficient output escaping presents a considerable XSS risk, and the absence of authorization checks on potential entry points is a notable weakness.
Key Concerns
- Output escaping is very poor (3% proper)
- No nonce checks on entry points
- No capability checks on entry points
Enhanced Recent Posts Security Vulnerabilities
Enhanced Recent Posts Code Analysis
Output Escaping
Enhanced Recent Posts Attack Surface
WordPress Hooks 3
Maintenance & Trust
Enhanced Recent Posts Maintenance & Trust
Maintenance Signals
Community Trust
Enhanced Recent Posts Alternatives
Latest Posts With Thumbnails and Ads
latest-posts-with-thumbnails-and-ads
Just like the default Recent Posts widget except that posts are with thumbnails and you can show ads between them, show post date and comments count.
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts
post-carousel
Display posts, pages, and taxonomies in beautiful carousel, slider, and grid layouts with advanced filtering. Customizable, Developer-friendly.
Recent Posts by Category Widget
recent-posts-by-category-widget
Just like the default Recent Posts widget except you can choose a category to pull posts from.
Expanding Archives
expanding-archives
This plugin adds a new widget where you can view your old posts by expanding certain years and months.
PE Recent Posts
pe-recent-posts
The simple plugin that allows you to display image slides with title, description and read more linked to posts from selected category.
Enhanced Recent Posts Developer Profile
4 plugins · 1K total installs
How We Detect Enhanced Recent Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/enhanced-recent-posts/css/enhanced-recent-posts.css/wp-content/plugins/enhanced-recent-posts/js/enhanced-recent-posts.js/wp-content/plugins/enhanced-recent-posts/js/enhanced-recent-posts.jsenhanced-recent-posts/css/enhanced-recent-posts.css?ver=enhanced-recent-posts/js/enhanced-recent-posts.js?ver=HTML / DOM Fingerprints
enhanced-recent-posts-widgetdata-enh-rp-widget-idENHANCED_RECENT_POSTS_USE_JAVASCRIPT