
Featured Posts Pro Security & Risk Analysis
wordpress.org/plugins/featured-posts-proThis plugin gives Administrator/Editor an easy option to mark posts, pages & custom posts as featured posts and provides a widget to list the rece …
Is Featured Posts Pro Safe to Use in 2026?
Generally Safe
Score 85/100Featured Posts Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "featured-posts-pro" v1.4 plugin exhibits a mixed security posture. While it boasts a clean vulnerability history with no known CVEs and demonstrates good practices like exclusively using prepared statements for SQL queries and performing a nonce and capability check on one of its entry points, significant concerns arise from its attack surface. The plugin has two AJAX handlers, both of which lack authentication checks. This is a critical oversight as it exposes direct entry points for unauthenticated attackers to potentially manipulate the plugin's functionality. Furthermore, the taint analysis revealed a flow with an unsanitized path, which, while not classified as critical or high severity, warrants attention. The low percentage of properly escaped output (24%) also increases the risk of cross-site scripting (XSS) vulnerabilities, especially given the unprotected AJAX endpoints. In conclusion, the plugin has strengths in its SQL handling and lack of historical vulnerabilities, but the unprotected AJAX endpoints and the unsanitized path flow represent substantial security risks that need immediate remediation.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized path flow
- Low percentage of escaped output
Featured Posts Pro Security Vulnerabilities
Featured Posts Pro Release Timeline
Featured Posts Pro Code Analysis
Output Escaping
Data Flow Analysis
Featured Posts Pro Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
Featured Posts Pro Maintenance & Trust
Maintenance Signals
Community Trust
Featured Posts Pro Alternatives
Featured Post Creative
featured-post-creative
Display Featured post on your website with 2 shortcode and 1 widget. Also work with Gutenberg shortcode block.
Relevant – Related, Featured, Latest, and Popular Posts by BestWebSoft
relevant
Add related, featured, latest, and popular posts to your WordPress website. Connect your blog readers with a relevant content.
Recent & Featured Posts Widget
recent-featured-posts-widget
Display recent posts or manually selected posts with thumbnail images. Show the excerpt directly on the page or as a dropdown.
AK Featured Post Widget
akfeatured-post-widget
A widget that you can use to display your blog posts, custom post types, or woocommerce products!
Nelio Featured Posts
nelio-featured-posts
Select the featured posts you want to show at any time and include them in your theme using a widget.
Featured Posts Pro Developer Profile
3 plugins · 410 total installs
How We Detect Featured Posts Pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/featured-posts-pro/css/featured_posts_pro-admin.css/wp-content/plugins/featured-posts-pro/css/jquery-ui-1.12.1.custom/jquery-ui.min.css/wp-content/plugins/featured-posts-pro/css/jquery-ui-1.12.1.custom/jquery-ui.theme.min.css/wp-content/plugins/featured-posts-pro/js/jquery-ui-1.12.1.custom/jquery-ui.min.js/wp-content/plugins/featured-posts-pro/js/featured_posts_pro-admin.jshttps://maxcdn.bootstrapcdn.com/font-awesome/4.6.3/css/font-awesome.min.cssfeatured-posts-pro/css/featured_posts_pro-admin.css?ver=featured-posts-pro/css/jquery-ui-1.12.1.custom/jquery-ui.min.css?ver=featured-posts-pro/css/jquery-ui-1.12.1.custom/jquery-ui.theme.min.css?ver=featured-posts-pro/js/jquery-ui-1.12.1.custom/jquery-ui.min.js?ver=featured-posts-pro/js/featured_posts_pro-admin.js?ver=HTML / DOM Fingerprints
name="is_post_featured"name="featured_posts_pro_nounce"