
Feature Me – CTA Widget Security & Risk Analysis
wordpress.org/plugins/feature-meA simple widget that allows you to feature any page or post on your website.
Is Feature Me – CTA Widget Safe to Use in 2026?
Generally Safe
Score 85/100Feature Me – CTA Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "feature-me" plugin v1.1.3 presents a surprisingly clean security posture based on the static analysis provided. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface, and critically, all identified entry points are either absent or appear to be protected by authorization checks. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding file operations or external HTTP requests. There are no identified dangerous functions or critical/high severity taint flows. The vulnerability history is also completely clean, with no recorded CVEs, suggesting a lack of publicly known vulnerabilities or a history of prompt patching.
However, a notable concern is the low percentage (22%) of properly escaped output. This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is being outputted without sufficient sanitization. While the attack surface is small and no direct exploitable paths were found in the taint analysis, a single unescaped output could still lead to a serious security incident. The complete lack of nonces and capability checks, while not directly tied to an observed vulnerability in this snapshot, are standard security best practices for protecting WordPress functionality and could be leveraged in conjunction with an unescaped output to escalate privileges or perform unauthorized actions if specific entry points were ever introduced or discovered.
In conclusion, "feature-me" v1.1.3 shows a strong foundation in terms of attack surface reduction and secure data handling for SQL. Its clean vulnerability history is a significant positive. The primary weakness lies in the insufficient output escaping, which poses a genuine XSS risk. While the current analysis doesn't reveal exploitable vulnerabilities, this area requires immediate attention and remediation to ensure a robust security posture.
Key Concerns
- Insufficient output escaping (22%)
- Missing nonce checks
- Missing capability checks
Feature Me – CTA Widget Security Vulnerabilities
Feature Me – CTA Widget Code Analysis
Output Escaping
Feature Me – CTA Widget Attack Surface
WordPress Hooks 4
Maintenance & Trust
Feature Me – CTA Widget Maintenance & Trust
Maintenance Signals
Community Trust
Feature Me – CTA Widget Alternatives
Feature A Page Widget
feature-a-page-widget
A widget to display an attractive summary of any page in any widget area.
Advanced Featured Page Widget
advanced-featured-page-widget
This plugin allows you to add a featured page using a widget.
Genesis Featured Page Advanced
genesis-featured-page-advanced
An advanced version of the Genesis - Featured Page widget. Allows you to add a custom image, custom content, page excerpt, and more.
Featured Post Creative
featured-post-creative
Display Featured post on your website with 2 shortcode and 1 widget. Also work with Gutenberg shortcode block.
AK Featured Post Widget
akfeatured-post-widget
A widget that you can use to display your blog posts, custom post types, or woocommerce products!
Feature Me – CTA Widget Developer Profile
1 plugin · 60 total installs
How We Detect Feature Me – CTA Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feature-me/featureme.css/wp-content/plugins/feature-me/js/featureMeWidget.jsHTML / DOM Fingerprints
feature-me