Genesis Sandbox Featured Content Widget Security & Risk Analysis

wordpress.org/plugins/genesis-featured-content-widget

Genesis Featured Content with support for custom post types, taxonomies, and so much more.

1K active installs v1.2.6 PHP + WP 3.6+ Updated Nov 29, 2017
cufeatured-postgenesisgenesiswpstudiopress
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Genesis Sandbox Featured Content Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Genesis Sandbox Featured Content Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin "genesis-featured-content-widget" v1.2.6 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface, and notably, there are no unprotected entry points. The code analysis reveals good practices, with no dangerous functions, file operations, or external HTTP requests. All detected SQL queries utilize prepared statements, and there are no critical or high-severity taint flows, indicating a lack of exploitable data flow issues.

However, there are minor areas for improvement. While the majority of output is properly escaped (73%), the remaining 27% could potentially lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is involved in those outputs. The complete absence of nonce and capability checks, while mitigated by the small attack surface, represents a missed opportunity for hardening and could become a concern if new entry points were introduced in future versions.

The plugin's vulnerability history is spotless, with zero known CVEs and no recorded past vulnerabilities. This suggests a history of secure development and maintenance. In conclusion, "genesis-featured-content-widget" v1.2.6 is a well-secured plugin with a minimal attack surface and no significant known vulnerabilities. The primary concern is the possibility of unescaped output, and the lack of specific security checks, though not currently exploitable given the limited entry points, are minor weaknesses.

Key Concerns

  • Some output is not properly escaped
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Genesis Sandbox Featured Content Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Genesis Sandbox Featured Content Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
12
33 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

73% escaped45 total outputs
Attack Surface

Genesis Sandbox Featured Content Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 39
actiongenesis_initgs-featured-content-widget.php:58
actionwidgets_initgs-featured-content-widget.php:74
filterplugin_action_linksgs-featured-content-widget.php:94
actionsave_postgs-featured-content-widget.php:112
actiongenesis_initgsfc-settings.php:40
actionafter_setup_themegsfc-settings.php:52
actiongenesis_admin_before_metaboxesgsfc-settings.php:53
actiongenesis_theme_settings_defaultsgsfc-settings.php:54
filtergsfc_defaultswidget-extension.php:18
filtergsfc_form_fieldswidget-extension.php:19
filtergsfc_updatewidget-extension.php:20
actiongsfc_before_post_contentwidget-extension.php:22
actiongsfc_post_contentwidget-extension.php:23
actiongsfc_after_post_contentwidget-extension.php:24
actiongsfc_output_form_fieldswidget.php:156
filterpost_classwidget.php:159
filterexcerpt_lengthwidget.php:162
filterexcerpt_morewidget.php:163
filtergenesis_attr_gsfc-entry-image-widgetwidget.php:166
actiongsfc_before_post_contentwidget.php:167
actiongsfc_post_contentwidget.php:168
actiongsfc_after_post_contentwidget.php:169
actiongsfc_before_post_contentwidget.php:172
actiongsfc_before_post_contentwidget.php:173
actiongsfc_widget_titlewidget.php:176
actiongsfc_before_post_contentwidget.php:179
actiongsfc_post_contentwidget.php:180
actiongsfc_after_post_contentwidget.php:181
actiongsfc_post_contentwidget.php:184
actiongsfc_after_post_contentwidget.php:187
actiongsfc_endwhilewidget.php:190
actiongsfc_after_loop_resetwidget.php:193
actiongsfc_after_loop_resetwidget.php:194
actionadmin_enqueue_scriptswidget.php:197
actionadmin_print_footer_scriptswidget.php:198
actiongsfc_before_widgetwidget.php:201
filterexcerpt_morewidget.php:513
filterpost_classwidget.php:1969
filterpost_limitswidget.php:1972
Maintenance & Trust

Genesis Sandbox Featured Content Widget Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedNov 29, 2017
PHP min version
Downloads32K

Community Trust

Rating100/100
Number of ratings14
Active installs1K
Developer Profile

Genesis Sandbox Featured Content Widget Developer Profile

Travis Smith

11 plugins · 2K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Genesis Sandbox Featured Content Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/genesis-featured-content-widget/style.css
Version Parameters
genesis-featured-content-widget/style.css?ver=gsfc_script.js?ver=

HTML / DOM Fingerprints

CSS Classes
gsfc-widget
FAQ

Frequently Asked Questions about Genesis Sandbox Featured Content Widget