LH Related Posts by Taxonomy Security & Risk Analysis

wordpress.org/plugins/lh-related-posts-by-taxonomy

A lightweight decisions not options related posts plugin.

0 active installs v1.00 PHP + WP 5.2+ Updated Aug 9, 2022
postsrelatedrelated-postssimilarthumbnails
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LH Related Posts by Taxonomy Safe to Use in 2026?

Generally Safe

Score 85/100

LH Related Posts by Taxonomy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin 'lh-related-posts-by-taxonomy' v1.00 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and includes a nonce check for its single AJAX handler. Crucially, there are no recorded vulnerabilities (CVEs) for this plugin, suggesting a history of stable and secure development. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security.

However, a key area for improvement lies in output escaping. With only 41% of outputs properly escaped, there is a significant risk of cross-site scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through user-generated content or other data points that are displayed without adequate sanitization. Additionally, the plugin lacks capability checks for its AJAX handler, meaning any authenticated user, regardless of their role or permissions, could potentially interact with this entry point. While the total attack surface is small and only has one entry point, the lack of granular access control on this point is a concern.

In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL handling, the insufficient output escaping and the absence of capability checks on its AJAX handler present tangible security risks that should be addressed to further harden its security profile.

Key Concerns

  • Insufficient output escaping detected.
  • Missing capability checks on AJAX handler.
Vulnerabilities
None known

LH Related Posts by Taxonomy Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LH Related Posts by Taxonomy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
24
17 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

41% escaped41 total outputs
Attack Surface

LH Related Posts by Taxonomy Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_taxonomy_single_term_addincludes\class.taxonomy-single-term.php:146
WordPress Hooks 14
actionadd_meta_boxesincludes\class.taxonomy-single-term.php:144
actionadmin_footerincludes\class.taxonomy-single-term.php:145
actionset_object_termsincludes\class.taxonomy-single-term.php:536
actionwp_footerincludes\lh-register-file-class.php:181
actionembed_footerincludes\lh-register-file-class.php:182
filterlh_web_application_precache_static_urls_filterincludes\lh-register-file-class.php:190
filterscript_loader_tagincludes\lh-register-file-class.php:236
filterstyle_loader_tagincludes\lh-register-file-class.php:237
filterthe_contentlh-related-posts-by-taxonomy.php:343
actionwp_body_openlh-related-posts-by-taxonomy.php:441
actioninitlh-related-posts-by-taxonomy.php:444
actionafter_setup_themelh-related-posts-by-taxonomy.php:447
actionwp_loadedlh-related-posts-by-taxonomy.php:450
actionplugins_loadedlh-related-posts-by-taxonomy.php:482
Maintenance & Trust

LH Related Posts by Taxonomy Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedAug 9, 2022
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LH Related Posts by Taxonomy Developer Profile

shawfactor

77 plugins · 15K total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect LH Related Posts by Taxonomy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lh-related-posts-by-taxonomy/lh-related-posts-by-taxonomy-templates/default-template.php
Version Parameters
lh-related-posts-by-taxonomy/style.css?ver=

HTML / DOM Fingerprints

Shortcode Output
[lh_rpbt_display]
FAQ

Frequently Asked Questions about LH Related Posts by Taxonomy