Featured Post with thumbnail Security & Risk Analysis
wordpress.org/plugins/featured-post-with-thumbnailA really simple way of putting featured posts on your website.
Is Featured Post with thumbnail Safe to Use in 2026?
Generally Safe
Score 85/100Featured Post with thumbnail has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "featured-post-with-thumbnail" plugin v1.5.2 exhibits a mixed security posture. While the static analysis indicates a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks, several significant concerns are present. The complete lack of output escaping (0% properly escaped) is a critical weakness, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the absence of nonce checks and capability checks, coupled with the fact that all identified flows with unsanitized paths are not properly handled, indicates potential vulnerabilities related to unauthorized actions or data manipulation, especially given the file operation count. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, this history, combined with the current code signals, suggests a potential for undiscovered vulnerabilities due to the identified code quality issues, particularly around output sanitation and lack of checks.
Key Concerns
- 0% output escaping
- No nonce checks
- No capability checks
- Unsanitized paths in taint flows
Featured Post with thumbnail Security Vulnerabilities
Featured Post with thumbnail Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Featured Post with thumbnail Attack Surface
WordPress Hooks 8
Maintenance & Trust
Featured Post with thumbnail Maintenance & Trust
Maintenance Signals
Community Trust
Featured Post with thumbnail Alternatives
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Advanced Random Posts Widget
advanced-random-posts-widget
Provides flexible and advanced random posts. Display it via shortcode or widget with thumbnails, post excerpt, and much more!
Smart Recent Posts Widget
smart-recent-posts-widget
Provides advanced recent posts widget,you can display it with thumbnails, excerpt, date, author, comment count and more.
Amazing Posts Widget
amazing-post-widget
Display Posts on widget with amazing way, It's really suitable with your blog or portfolio.
Recent Post Widget Thumbnail
recent-post-widget-thumbnail
Gives adaptable and highly organized recent posts. Show it through widget with thumbnails, post excerpt, post date.
Featured Post with thumbnail Developer Profile
1 plugin · 400 total installs
How We Detect Featured Post with thumbnail
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/featured-post-with-thumbnail/featured-post.cssHTML / DOM Fingerprints
yiw-featured-postfeatured-thumbfeatured-title/*
* @package Featured Posts
* @author Nando Pappalardo e Giustino Borzacchiello
* @version 1.5.2
*//*
Plugin Name: Featured Post with thumbnail
Plugin URI: http://www.yourinspirationweb.com/en/wordpress-plugin-featured-posts-with-thumbnails-highlighting-your-best-articles/
Description: This widget allows you to add in your blog's sidebar a list of featured post with thumbanil.
Author: Nando Pappalardo e Giustino Borzacchiello
Version: 1.5.2
Author URI: http://en.yourinspirationweb.com/
USAGE:
LICENCE:
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
*//**
* Load configuration files
*//**
* Aggiunge il CSS del plugin
* Enqueue plugin CSS file
*/+8 moreid="yiw-featured-post"class="featured-thumb"class="alignleft"class="featured-title"name="insert_featured_post"id="insert_featured_post"+2 moreYIW_TEXT_DOMAIN