Genesis Featured Widget Amplified Security & Risk Analysis

wordpress.org/plugins/genesis-featured-widget-amplified

Genesis Featured Posts with support for custom post types, taxonomies, and so much more

2K active installs v0.9.2 PHP 5.2+ WP 3.3+ Updated Dec 22, 2017
custom-post-typefeatured-postgenesisgenesiswpstudiopress
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Genesis Featured Widget Amplified Safe to Use in 2026?

Generally Safe

Score 85/100

Genesis Featured Widget Amplified has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of "genesis-featured-widget-amplified" v0.9.2 reveals a strong security posture based on the provided data. The plugin exhibits no readily identifiable attack surface through AJAX, REST API, shortcodes, or cron events. Furthermore, the absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is highly commendable. The code also demonstrates a good practice of output escaping, with 82% of outputs being properly handled, though the remaining 18% warrants attention.

The lack of any recorded vulnerabilities, including critical or high-severity ones, and the absence of taint analysis findings contribute to a positive security assessment. This indicates that the development team has likely prioritized security and followed best practices. However, the complete absence of nonce checks and capability checks across all entry points (which are zero in this case) is a notable omission. While there are no current entry points to exploit, if the plugin were to evolve and introduce them without these security mechanisms, it could present a significant risk.

In conclusion, "genesis-featured-widget-amplified" v0.9.2 presents a low-risk profile due to its limited attack surface and lack of known vulnerabilities. The code signals are generally strong, with excellent handling of SQL and a good proportion of escaped output. The primary area for concern lies in the absence of security checks like nonces and capabilities, which, while not an immediate threat given the current state, represent a potential future risk if the plugin's functionality expands.

Key Concerns

  • Output escaping not fully implemented
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Genesis Featured Widget Amplified Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Genesis Featured Widget Amplified Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
85 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

82% escaped104 total outputs
Attack Surface

Genesis Featured Widget Amplified Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionwidgets_initinc\classes\class-genesis-featured-widget-amplified.php:34
actionwidgets_initinc\classes\class-genesis-featured-widget-amplified.php:43
filterpost_classinc\classes\class-genesis-featured-widget-amplified.php:159
filterpost_limitsinc\classes\class-genesis-featured-widget-amplified.php:162
actiongfwa_before_post_contentinc\classes\class-genesis-featured-widget-amplified.php:1062
actiongfwa_post_contentinc\classes\class-genesis-featured-widget-amplified.php:1063
actiongfwa_after_post_contentinc\classes\class-genesis-featured-widget-amplified.php:1064
actiongfwa_before_post_contentinc\classes\class-genesis-featured-widget-amplified.php:1094
actiongfwa_before_post_contentinc\classes\class-genesis-featured-widget-amplified.php:1130
actiongfwa_before_post_contentinc\classes\class-genesis-featured-widget-amplified.php:1153
actiongfwa_post_contentinc\classes\class-genesis-featured-widget-amplified.php:1169
actiongfwa_after_post_contentinc\classes\class-genesis-featured-widget-amplified.php:1194
actionadmin_print_footer_scriptsinc\classes\class-genesis-featured-widget-amplified.php:1264
actiongenesis_initplugin.php:45
Maintenance & Trust

Genesis Featured Widget Amplified Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedDec 22, 2017
PHP min version5.2
Downloads91K

Community Trust

Rating98/100
Number of ratings15
Active installs2K
Developer Profile

Genesis Featured Widget Amplified Developer Profile

Nick the Geek

6 plugins · 3K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Genesis Featured Widget Amplified

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/genesis-featured-widget-amplified/inc/css/widget.css/wp-content/plugins/genesis-featured-widget-amplified/inc/js/widget.js
Script Paths
/wp-content/plugins/genesis-featured-widget-amplified/inc/js/widget.js
Version Parameters
genesis-featured-widget-amplified/inc/css/widget.css?ver=genesis-featured-widget-amplified/inc/js/widget.js?ver=

HTML / DOM Fingerprints

CSS Classes
featured-contentfeaturedpostgfwa-post-imagegfwa-post-titlegfwa-post-metagfwa-post-contentgfwa-more-link
HTML Comments
<!-- To Do: -->
Data Attributes
data-image-sizedata-image-alignmentdata-gravatar-sizedata-gravatar-alignment
JS Globals
gfwa_counter
Shortcode Output
[post_date][post_author_posts_link][post_comments][post_categories]
FAQ

Frequently Asked Questions about Genesis Featured Widget Amplified