Get Post List With Thumbnails Security & Risk Analysis
wordpress.org/plugins/get-post-list-with-thumbnailsDescription:Displays a list with posts and custom size thumbnails(for the first attached or featured image), linked to each post permalink.
Is Get Post List With Thumbnails Safe to Use in 2026?
Generally Safe
Score 85/100Get Post List With Thumbnails has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'get-post-list-with-thumbnails' v10.0.2 plugin exhibits a generally good security posture in several key areas. The static analysis shows no dangerous functions, all SQL queries utilize prepared statements, and there are no external HTTP requests or file operations that could be exploited. The absence of known CVEs and a clean vulnerability history further contribute to this positive outlook, suggesting a mature and well-maintained codebase.
However, a significant concern arises from the complete lack of output escaping for all 182 identified output points. This is a critical weakness that leaves the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed to users, if not properly sanitized before output, could be manipulated by attackers to inject malicious scripts. While the attack surface is small and appears to have no unprotected entry points, the severity of unescaped output cannot be overstated. Therefore, while the plugin avoids common pitfalls like unpatched vulnerabilities and raw SQL, the lack of output escaping presents a substantial risk that requires immediate attention.
Key Concerns
- All outputs are unescaped
Get Post List With Thumbnails Security Vulnerabilities
Get Post List With Thumbnails Release Timeline
Get Post List With Thumbnails Code Analysis
Output Escaping
Get Post List With Thumbnails Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Get Post List With Thumbnails Maintenance & Trust
Maintenance Signals
Community Trust
Get Post List With Thumbnails Alternatives
Recent Posts by Category (RCP)
recent-posts-by-category-rcp
Display recent posts from any category as a modern, stylish widget on any page on your website.
WAD Recent Posts
wad-recent-posts
Simple and clean widget for showing recent posts list. It also has shortcode feature.
Unlist Posts & Pages
unlist-posts
Hide posts, pages or custom items from your site and make them accessible only with the direct link.
Latest Posts Block – Dynamic Posts Grid, Posts List, Posts Tile with Stunning Layouts for WordPress Blogs & Pages
latest-posts-block-lite
Dynamic Posts Grid, Posts List, Posts Tile with Stunning Layouts for WordPress Blogs & Pages
Flex Posts – Widget and Gutenberg Block
flex-posts
A widget to display posts with thumbnails in various layouts. Fits nicely in any widget area size.
Get Post List With Thumbnails Developer Profile
4 plugins · 250 total installs
How We Detect Get Post List With Thumbnails
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/get-post-list-with-thumbnails/ajaxhandler.js/wp-content/plugins/get-post-list-with-thumbnails/ajaxhandlergplwt.jsHTML / DOM Fingerprints
Copyright 2013 Alvaro Neto (email : wpworking@wpworking.com This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or+8 moregoprocess_gplwtconsulta_gplwt[gplt]