
Latest Post Shortcode Security & Risk Analysis
wordpress.org/plugins/latest-post-shortcodeThe "Latest Post Shortcode" allows you to create a dynamic content selection from your posts by combining, limiting, and filtering what you need.
Is Latest Post Shortcode Safe to Use in 2026?
Generally Safe
Score 98/100Latest Post Shortcode has a strong security track record. Known vulnerabilities have been patched promptly.
The "latest-post-shortcode" plugin exhibits a mixed security posture. While it demonstrates good practices such as exclusively using prepared statements for SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface. The presence of three unprotected AJAX handlers presents a substantial risk, as these can be directly accessed by unauthenticated users, potentially leading to unauthorized actions or information disclosure. The lack of nonce checks on these AJAX endpoints further exacerbates this issue.
The vulnerability history is particularly noteworthy, with two past medium-severity CVEs related to Missing Authorization and Cross-Site Scripting. Although currently unpatched vulnerabilities are zero, the historical pattern of these specific vulnerability types suggests recurring issues with input validation and access control within the plugin. The fact that the last vulnerability was in 2026, while the current date is likely before that, could indicate a future unpatched vulnerability or an error in the provided data.
Key Concerns
- 3 unprotected AJAX handlers present
- Missing nonce checks on AJAX
- 2 historical medium CVEs
- Missing capability checks
Latest Post Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Latest Post Shortcode <= 14.2.0 - Missing Authorization
Latest Post Shortcode <= 14.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Latest Post Shortcode Code Analysis
SQL Query Safety
Output Escaping
Latest Post Shortcode Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 32
Maintenance & Trust
Latest Post Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Latest Post Shortcode Alternatives
Bokez – WordPress 5 Blocks
bokez-awesome-gutenberg-blocks
Build a beautiful website in minutes with best 15 essential Wordpress blocks. Customizable and super easy to use.
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Page Builder Gutenberg Blocks – CoBlocks
coblocks
CoBlocks is a suite of page builder WordPress blocks for Gutenberg, with 10+ new blocks and a true page builder experience with rows and columns.
Latest Post Shortcode Developer Profile
8 plugins · 21K total installs
How We Detect Latest Post Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/latest-post-shortcode/assets/css/frontend.css/wp-content/plugins/latest-post-shortcode/assets/css/slick.css/wp-content/plugins/latest-post-shortcode/assets/css/slick-theme.css/wp-content/plugins/latest-post-shortcode/assets/js/frontend.js/wp-content/plugins/latest-post-shortcode/assets/js/slick.min.js/wp-content/plugins/latest-post-shortcode/assets/js/frontend-admin.js/wp-content/plugins/latest-post-shortcode/assets/js/frontend.js/wp-content/plugins/latest-post-shortcode/assets/js/slick.min.js/wp-content/plugins/latest-post-shortcode/assets/js/frontend-admin.jsver=14.22ver=lps_asset_versionHTML / DOM Fingerprints
lps-shortcode-wrapperlps-cardlps-card-image-leftlps-card-image-rightlps-card-no-imagelps-tile-contentlps-slick-slider-wrapperlps-slick-wrapper+14 more<!-- Start Latest Post Shortcode --><!-- End Latest Post Shortcode --><!-- LPS: Shortcode Wrapper --><!-- LPS: Tile Pattern -->+9 moredata-lps-post-iddata-lps-target-blankdata-lps-read-more-textdata-lps-image-sizedata-lps-show-categoriesdata-lps-show-tags+21 moreLPSFrontendLPSAdminlps_vars/wp-json/lps/v1/settings/wp-json/lps/v1/posts[latest-selected-content]