Inline Related Posts Security & Risk Analysis

wordpress.org/plugins/intelly-related-posts

Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.

100K active installs v3.9.0 PHP 5.6+ WP 3.6.0+ Updated Jun 12, 2025
inline-related-postssimilar-postssuggestionsyarppzemanta
96
A · Safe
CVEs total7
Unpatched0
Last CVEMay 7, 2025
Safety Verdict

Is Inline Related Posts Safe to Use in 2026?

Generally Safe

Score 96/100

Inline Related Posts has a strong security track record. Known vulnerabilities have been patched promptly.

7 known CVEsLast CVE: May 7, 2025Updated 9mo ago
Risk Assessment

The plugin "intelly-related-posts" v3.9.0 exhibits a mixed security posture. On the positive side, the code demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output, which significantly reduces the risk of SQL injection and cross-site scripting vulnerabilities stemming from these areas. The presence of a substantial number of capability checks (14) and nonces (4) suggests an effort to secure its functionalities. However, a critical concern arises from the attack surface analysis, which reveals one AJAX handler without authentication checks. This represents a direct pathway for unauthenticated users to interact with potentially sensitive plugin functionality, creating an exploitable vulnerability.

The vulnerability history is a significant red flag. The plugin has a history of 7 known medium-severity CVEs, including Cross-site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Exposure of Sensitive Information. Although there are no currently unpatched CVEs and the last known vulnerability was in the future (which might be a data anomaly, but suggests recent patching), this pattern of past vulnerabilities indicates a recurring tendency for security weaknesses. The common types of past vulnerabilities align with potential risks that might be introduced by an unprotected AJAX endpoint.

In conclusion, while the plugin has strengths in its SQL and output handling, the presence of an unprotected AJAX endpoint and a history of multiple medium-severity vulnerabilities, particularly those related to input validation and authorization, present a notable risk. The historical pattern suggests a need for careful auditing and ongoing vigilance. The potential for exploitation of the unprotected AJAX handler, especially in light of past XSS and CSRF issues, should be prioritized.

Key Concerns

  • Unprotected AJAX handler
  • History of 7 medium severity CVEs
  • Bundled outdated library (Select2 v4.0.13)
Vulnerabilities
7

Inline Related Posts Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
5 CVEs in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
7

7 total CVEs

CVE-2025-47604medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Inline Related Posts <= 3.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 7, 2025 Patched in 3.9.0 (296d)
CVE-2024-6487medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Inline Related Posts <= 3.7.0 - Authenticated (Admin+) Stored Cross-Site Scripting

Jul 8, 2024 Patched in 3.8.0 (30d)
CVE-2024-5626medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Inline Related Posts <= 3.6.0 - Reflected Cross-Site Scripting

Jun 21, 2024 Patched in 3.7.0 (12d)
CVE-2024-31426medium · 4.3Cross-Site Request Forgery (CSRF)

Inline Related Posts <= 3.3.1 - Cross-Site Request Forgery

Apr 10, 2024 Patched in 3.4.0 (7d)
CVE-2023-6257medium · 4.3Exposure of Sensitive Information to an Unauthorized Actor

Inline Related Posts <= 3.5.0 - Information Exposure

Mar 21, 2024 Patched in 3.6.0 (27d)
CVE-2024-2444medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Inline Related Posts <= 3.4.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Mar 16, 2024 Patched in 3.5.0 (13d)
WF-2505ffdd-d697-4c69-8f75-0bc4d09e1b1f-intelly-related-postsmedium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Inline Related Posts <= 3.0.4 - Authenticated (Admin+) Cross-Site Scripting

Oct 9, 2021 Patched in 3.0.5 (836d)
Code Analysis
Analyzed Mar 16, 2026

Inline Related Posts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
1
211 escaped
Nonce Checks
4
Capability Checks
14
File Operations
2
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select24.0.13

SQL Query Safety

100% prepared8 total queries

Output Escaping

100% escaped212 total outputs
Attack Surface
1 unprotected

Inline Related Posts Attack Surface

Entry Points3
Unprotected1

AJAX Handlers 2

authwp_ajax_do_actionincludes\actions.php:6
authwp_ajax_irp_list_postsincludes\core.php:353

Shortcodes 1

[irp] includes\core.php:49
WordPress Hooks 20
actioninitincludes\actions.php:5
actionadmin_headincludes\admin\button-mce.php:2
filtermce_external_pluginsincludes\admin\button-mce.php:14
filtermce_buttonsincludes\admin\button-mce.php:15
actionadd_meta_boxesincludes\admin\metabox.php:18
actionsave_postincludes\admin\metabox.php:46
actionadmin_menuincludes\classes\ui\Tabs.php:8
filterplugin_action_linksincludes\classes\ui\Tabs.php:9
actionadmin_enqueue_scriptsincludes\classes\ui\Tabs.php:11
filtercron_schedulesincludes\classes\utils\Cron.php:25
actionwpincludes\classes\utils\Cron.php:26
actionirp_weekly_scheduled_eventsincludes\classes\utils\Tracking.php:18
filterwp_headincludes\core.php:2
filterwp_footerincludes\core.php:25
filterthe_contentincludes\core.php:226
filterposts_whereincludes\core.php:302
actionadmin_initincludes\install.php:15
actioninitindex.php:66
actionenqueue_block_editor_assetsindex.php:80
filterblock_categories_allindex.php:93

Scheduled Events 2

irp_weekly_scheduled_events
irp_daily_scheduled_events
Maintenance & Trust

Inline Related Posts Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 12, 2025
PHP min version5.6
Downloads1.6M

Community Trust

Rating86/100
Number of ratings77
Active installs100K
Developer Profile

Inline Related Posts Developer Profile

Data443 Risk Mitigation, Inc.

10 plugins · 213K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
411 days
View full developer profile
Detection Fingerprints

How We Detect Inline Related Posts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/intelly-related-posts/shortcode-block.js/wp-content/plugins/intelly-related-posts/assets/deps/select2-4.0.13/select2.min.css/wp-content/plugins/intelly-related-posts/assets/deps/select2-4.0.13/select2.full.min.js/wp-content/plugins/intelly-related-posts/assets/css/style.css/wp-content/plugins/intelly-related-posts/assets/js/common.js/wp-content/plugins/intelly-related-posts/assets/deps/select2-4.0.13/select2.min.css/wp-content/plugins/intelly-related-posts/assets/deps/select2-4.0.13/select2.full.min.js/wp-content/plugins/intelly-related-posts/assets/deps/starrr/starrr.js+2 more
Script Paths
/wp-content/plugins/intelly-related-posts/shortcode-block.js/wp-content/plugins/intelly-related-posts/assets/deps/select2-4.0.13/select2.full.min.js/wp-content/plugins/intelly-related-posts/assets/js/common.js/wp-content/plugins/intelly-related-posts/assets/deps/select2-4.0.13/select2.full.min.js/wp-content/plugins/intelly-related-posts/assets/deps/starrr/starrr.js/wp-content/plugins/intelly-related-posts/assets/deps/qtip/jquery.qtip.min.js
Version Parameters
intelly-related-posts/shortcode-block.js?ver=intelly-related-posts/assets/deps/select2-4.0.13/select2.min.css?ver=intelly-related-posts/assets/deps/select2-4.0.13/select2.full.min.js?ver=intelly-related-posts/assets/css/style.css?ver=intelly-related-posts/assets/js/common.js?ver=intelly-related-posts/assets/deps/select2-4.0.13/select2.min.css?ver=intelly-related-posts/assets/deps/select2-4.0.13/select2.full.min.js?ver=intelly-related-posts/assets/deps/starrr/starrr.js?ver=intelly-related-posts/assets/deps/qtip/jquery.qtip.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
irp-buttonirp-submit
HTML Comments
<!-- inline related posts --><!-- end inline related posts --><!-- inline related posts --><!-- end inline related posts -->
Data Attributes
data-irp-post-type
JS Globals
IRP_PLUGIN_PREFIXIRP_PLUGIN_FILEIRP_PLUGIN_SLUGIRP_PLUGIN_NAMEIRP_PLUGIN_VERSIONIRP_PLUGIN_AUTHOR+36 more
FAQ

Frequently Asked Questions about Inline Related Posts