
Featured Today Security & Risk Analysis
wordpress.org/plugins/featured-todayFeatured Today shows featured articles like it is shown on linkedin today.
Is Featured Today Safe to Use in 2026?
Generally Safe
Score 85/100Featured Today has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'featured-today' plugin version 1.0.4 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices by exclusively using prepared statements for SQL queries, performing no file operations, and making no external HTTP requests. The absence of recorded vulnerabilities in its history is also a positive indicator, suggesting a history of responsible development. However, several significant concerns warrant attention.
The static analysis reveals a critical issue with the use of the deprecated `create_function` function, which is known to be a potential security risk due to its inherent lack of sanitization and ability to execute arbitrary code. Furthermore, the plugin exhibits a very low percentage of properly escaped output (21%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks across all identified entry points (though zero in number) means that if any new entry points are introduced or discovered, they would be unprotected by these fundamental security mechanisms. The inclusion of an outdated jQuery library (v1.6.1) also presents a risk, as older versions often contain known vulnerabilities.
In conclusion, while the plugin's SQL handling and lack of external interactions are commendable, the prevalent risk of XSS due to poor output escaping, the use of a dangerous deprecated function, and the outdated bundled library collectively create a substantial security risk. The vulnerability history, while clean, does not negate the immediate threats identified in the static analysis. Developers should prioritize addressing the output escaping and the use of `create_function`.
Key Concerns
- Unescaped output (21% proper)
- Dangerous function used (create_function)
- Bundled outdated library (jQuery v1.6.1)
- Missing nonce checks
- Missing capability checks
Featured Today Security Vulnerabilities
Featured Today Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Featured Today Attack Surface
WordPress Hooks 1
Maintenance & Trust
Featured Today Maintenance & Trust
Maintenance Signals
Community Trust
Featured Today Alternatives
Yet Another Featured Posts Plugin (YAFPP)
yet-another-featured-posts-plugin
Yet Another Featured Posts Plugin provides an easy AJAX interface to feature posts, with thumbnails & other display options for featured posts.
ZK Advanced Feature Post
zk-advanced-feature-post
AJAX feature post function for your wordpress. Especially you can get featured post for custom category only.
Featured Post Creative
featured-post-creative
Display Featured post on your website with 2 shortcode and 1 widget. Also work with Gutenberg shortcode block.
Mark Posts
mark-posts
Mark and highlight posts, pages and posts of custom post types within the posts overview.
Relevant – Related, Featured, Latest, and Popular Posts by BestWebSoft
relevant
Add related, featured, latest, and popular posts to your WordPress website. Connect your blog readers with a relevant content.
Featured Today Developer Profile
2 plugins · 20 total installs
How We Detect Featured Today
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/featured-today/css/featured.css/wp-content/plugins/featured-today/js/jquery-1.6.2.min.js/wp-content/plugins/featured-today/js/jquery-1.6.2.min.jsHTML / DOM Fingerprints
article-linktextimageimage-offsetshare-ribbonarrowid="linkdin-today"id="yui-gen9"jQuery