LH Jetpack Related Posts Security & Risk Analysis

wordpress.org/plugins/lh-jetpack-related-posts

Enables you to customise Jetpack Related post results through a GUI

10 active installs v1.07 PHP + WP 4.0+ Updated Jan 15, 2018
jetpackposts-2-postsrelated-posts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LH Jetpack Related Posts Safe to Use in 2026?

Generally Safe

Score 85/100

LH Jetpack Related Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'lh-jetpack-related-posts' v1.07 plugin exhibits a generally strong security posture based on the provided static analysis. It has zero known vulnerabilities (CVEs) and no critical or high severity taint flows, indicating a well-maintained and likely secure codebase. The plugin demonstrates good practices by using prepared statements for all SQL queries and including nonce checks and capability checks in its code. The absence of file operations and external HTTP requests further reduces the attack surface. However, a notable concern is the low rate of output escaping, with only 15% of the 20 identified outputs being properly escaped. This leaves a significant portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks if user-controlled data is displayed without sufficient sanitization. Despite this, the overall low attack surface and lack of critical code signals suggest a relatively low risk profile.

Key Concerns

  • Low output escaping rate
Vulnerabilities
None known

LH Jetpack Related Posts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LH Jetpack Related Posts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
17
3 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

15% escaped20 total outputs
Attack Surface

LH Jetpack Related Posts Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionadd_meta_boxeslh-jetpack-related-posts.php:438
actionsave_postlh-jetpack-related-posts.php:439
actionp2p_initlh-jetpack-related-posts.php:440
filterp2p_admin_box_showlh-jetpack-related-posts.php:442
filterjetpack_relatedposts_filter_optionslh-jetpack-related-posts.php:444
filterjetpack_relatedposts_filter_enabled_for_requestlh-jetpack-related-posts.php:446
filterjetpack_relatedposts_filter_post_typelh-jetpack-related-posts.php:447
filterjetpack_relatedposts_filter_hitslh-jetpack-related-posts.php:448
filterlh_instant_articles_related_articles_filterlh-jetpack-related-posts.php:450
actionadmin_menulh-jetpack-related-posts.php:454
filterplugin_action_linkslh-jetpack-related-posts.php:455
actionadmin_enqueue_scriptslh-jetpack-related-posts.php:458
actionplugins_loadedlh-jetpack-related-posts.php:461
filterjetpack_images_get_imageslh-jetpack-related-posts.php:464
Maintenance & Trust

LH Jetpack Related Posts Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 15, 2018
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

LH Jetpack Related Posts Developer Profile

shawfactor

77 plugins · 15K total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect LH Jetpack Related Posts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lh-jetpack-related-posts/scripts/uploader.js
Script Paths
/wp-content/plugins/lh-jetpack-related-posts/scripts/uploader.js
Version Parameters
lh-jetpack-related-posts/scripts/uploader.js?ver=

HTML / DOM Fingerprints

Data Attributes
name="lh_jetpack_related_posts-disable_related_posts"id="lh_jetpack_related_posts-disable_related_posts"name="lh_jetpack_related_posts-disable-nonce"name="lh_jetpack_related_posts-backend_nonce"
FAQ

Frequently Asked Questions about LH Jetpack Related Posts