
LH Related Posts by Taxonomy Security & Risk Analysis
wordpress.org/plugins/lh-related-posts-by-taxonomyA lightweight decisions not options related posts plugin.
Is LH Related Posts by Taxonomy Safe to Use in 2026?
Generally Safe
Score 85/100LH Related Posts by Taxonomy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'lh-related-posts-by-taxonomy' v1.00 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and includes a nonce check for its single AJAX handler. Crucially, there are no recorded vulnerabilities (CVEs) for this plugin, suggesting a history of stable and secure development. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security.
However, a key area for improvement lies in output escaping. With only 41% of outputs properly escaped, there is a significant risk of cross-site scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through user-generated content or other data points that are displayed without adequate sanitization. Additionally, the plugin lacks capability checks for its AJAX handler, meaning any authenticated user, regardless of their role or permissions, could potentially interact with this entry point. While the total attack surface is small and only has one entry point, the lack of granular access control on this point is a concern.
In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL handling, the insufficient output escaping and the absence of capability checks on its AJAX handler present tangible security risks that should be addressed to further harden its security profile.
Key Concerns
- Insufficient output escaping detected.
- Missing capability checks on AJAX handler.
LH Related Posts by Taxonomy Security Vulnerabilities
LH Related Posts by Taxonomy Code Analysis
SQL Query Safety
Output Escaping
LH Related Posts by Taxonomy Attack Surface
AJAX Handlers 1
WordPress Hooks 14
Maintenance & Trust
LH Related Posts by Taxonomy Maintenance & Trust
Maintenance Signals
Community Trust
LH Related Posts by Taxonomy Alternatives
Related Posts Thumbnails Plugin for WordPress
related-posts-thumbnails
Related Posts by WPBrigade is The Best Customizable plugin, that nicely displays related posts thumbnails under the post.
Wp-Thumbie – Related Posts with thumbnails for WordPress
wp-thumbie
Show user defined number of related / similar posts with thumbnail image
Inline Related Posts
intelly-related-posts
Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
YARPP – Yet Another Related Posts Plugin
yet-another-related-posts-plugin
The best WordPress plugin for displaying related posts. Simple and flexible, with a powerful proven algorithm and inbuilt caching.
Contextual Related Posts
contextual-related-posts
Keep visitors on your site longer with intelligent, fast-loading, contextually related posts. Block, shortcode, custom post type and widget ready.
LH Related Posts by Taxonomy Developer Profile
77 plugins · 15K total installs
How We Detect LH Related Posts by Taxonomy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lh-related-posts-by-taxonomy/lh-related-posts-by-taxonomy-templates/default-template.phplh-related-posts-by-taxonomy/style.css?ver=HTML / DOM Fingerprints
[lh_rpbt_display]