
Inline Related Posts Security & Risk Analysis
wordpress.org/plugins/intelly-related-postsInline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
Is Inline Related Posts Safe to Use in 2026?
Generally Safe
Score 96/100Inline Related Posts has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "intelly-related-posts" v3.9.0 exhibits a mixed security posture. On the positive side, the code demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output, which significantly reduces the risk of SQL injection and cross-site scripting vulnerabilities stemming from these areas. The presence of a substantial number of capability checks (14) and nonces (4) suggests an effort to secure its functionalities. However, a critical concern arises from the attack surface analysis, which reveals one AJAX handler without authentication checks. This represents a direct pathway for unauthenticated users to interact with potentially sensitive plugin functionality, creating an exploitable vulnerability.
The vulnerability history is a significant red flag. The plugin has a history of 7 known medium-severity CVEs, including Cross-site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Exposure of Sensitive Information. Although there are no currently unpatched CVEs and the last known vulnerability was in the future (which might be a data anomaly, but suggests recent patching), this pattern of past vulnerabilities indicates a recurring tendency for security weaknesses. The common types of past vulnerabilities align with potential risks that might be introduced by an unprotected AJAX endpoint.
In conclusion, while the plugin has strengths in its SQL and output handling, the presence of an unprotected AJAX endpoint and a history of multiple medium-severity vulnerabilities, particularly those related to input validation and authorization, present a notable risk. The historical pattern suggests a need for careful auditing and ongoing vigilance. The potential for exploitation of the unprotected AJAX handler, especially in light of past XSS and CSRF issues, should be prioritized.
Key Concerns
- Unprotected AJAX handler
- History of 7 medium severity CVEs
- Bundled outdated library (Select2 v4.0.13)
Inline Related Posts Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
Inline Related Posts <= 3.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Inline Related Posts <= 3.7.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Inline Related Posts <= 3.6.0 - Reflected Cross-Site Scripting
Inline Related Posts <= 3.3.1 - Cross-Site Request Forgery
Inline Related Posts <= 3.5.0 - Information Exposure
Inline Related Posts <= 3.4.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Inline Related Posts <= 3.0.4 - Authenticated (Admin+) Cross-Site Scripting
Inline Related Posts Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Inline Related Posts Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 20
Scheduled Events 2
Maintenance & Trust
Inline Related Posts Maintenance & Trust
Maintenance Signals
Community Trust
Inline Related Posts Alternatives
Related Posts for WordPress
related-posts-for-wp
The best WordPress plugin for related posts. Simple, flexible, powerful algorithm, and built-in caching. Fully setup with only 1 click!
Internal Linking of Related Contents
internal-linking-of-related-contents
Internal Linking of Related Contents allows you to automatically insert inline related posts within your WordPress articles.
SPAI – Similar posts AI Plugin
similar-posts-ai-spai
Creates an AI-based recommended articles widget. The fastest plugin, since all calculations take place on the developer's servers.
YARPP – Yet Another Related Posts Plugin
yet-another-related-posts-plugin
The best WordPress plugin for displaying related posts. Simple and flexible, with a powerful proven algorithm and inbuilt caching.
Contextual Related Posts
contextual-related-posts
Keep visitors on your site longer with intelligent, fast-loading, contextually related posts. Block, shortcode, custom post type and widget ready.
Inline Related Posts Developer Profile
10 plugins · 213K total installs
How We Detect Inline Related Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/intelly-related-posts/shortcode-block.js/wp-content/plugins/intelly-related-posts/assets/deps/select2-4.0.13/select2.min.css/wp-content/plugins/intelly-related-posts/assets/deps/select2-4.0.13/select2.full.min.js/wp-content/plugins/intelly-related-posts/assets/css/style.css/wp-content/plugins/intelly-related-posts/assets/js/common.js/wp-content/plugins/intelly-related-posts/assets/deps/select2-4.0.13/select2.min.css/wp-content/plugins/intelly-related-posts/assets/deps/select2-4.0.13/select2.full.min.js/wp-content/plugins/intelly-related-posts/assets/deps/starrr/starrr.js+2 more/wp-content/plugins/intelly-related-posts/shortcode-block.js/wp-content/plugins/intelly-related-posts/assets/deps/select2-4.0.13/select2.full.min.js/wp-content/plugins/intelly-related-posts/assets/js/common.js/wp-content/plugins/intelly-related-posts/assets/deps/select2-4.0.13/select2.full.min.js/wp-content/plugins/intelly-related-posts/assets/deps/starrr/starrr.js/wp-content/plugins/intelly-related-posts/assets/deps/qtip/jquery.qtip.min.jsintelly-related-posts/shortcode-block.js?ver=intelly-related-posts/assets/deps/select2-4.0.13/select2.min.css?ver=intelly-related-posts/assets/deps/select2-4.0.13/select2.full.min.js?ver=intelly-related-posts/assets/css/style.css?ver=intelly-related-posts/assets/js/common.js?ver=intelly-related-posts/assets/deps/select2-4.0.13/select2.min.css?ver=intelly-related-posts/assets/deps/select2-4.0.13/select2.full.min.js?ver=intelly-related-posts/assets/deps/starrr/starrr.js?ver=intelly-related-posts/assets/deps/qtip/jquery.qtip.min.js?ver=HTML / DOM Fingerprints
irp-buttonirp-submit<!-- inline related posts --><!-- end inline related posts --><!-- inline related posts --><!-- end inline related posts -->data-irp-post-typeIRP_PLUGIN_PREFIXIRP_PLUGIN_FILEIRP_PLUGIN_SLUGIRP_PLUGIN_NAMEIRP_PLUGIN_VERSIONIRP_PLUGIN_AUTHOR+36 more