
Mark New Posts Security & Risk Analysis
wordpress.org/plugins/mark-new-postsHighlight unread posts on your blog.
Is Mark New Posts Safe to Use in 2026?
Generally Safe
Score 91/100Mark New Posts has a strong security track record. Known vulnerabilities have been patched promptly.
The 'mark-new-posts' plugin version 7.6 exhibits a generally positive security posture with some notable areas for improvement. The static analysis reveals a very small attack surface, with only one AJAX handler, and importantly, no unprotected entry points. The code also demonstrates good practices by using prepared statements for all SQL queries and implementing nonce and capability checks, indicating an awareness of common web vulnerabilities. However, a significant concern arises from the output escaping, where only 36% of outputs are properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered directly without sanitization. The vulnerability history shows one known CVE, a medium severity issue classified as Missing Authorization, which has since been patched. While the absence of currently unpatched vulnerabilities is reassuring, the past occurrence of a missing authorization flaw suggests that thorough permission checks are crucial for this plugin.
Key Concerns
- Insecure output escaping detected
- Past medium severity vulnerability (Missing Authorization)
Mark New Posts Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Mark New Posts <= 7.5.1 - Missing Authorization via save_options
Mark New Posts Code Analysis
Output Escaping
Mark New Posts Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
Mark New Posts Maintenance & Trust
Maintenance Signals
Community Trust
Mark New Posts Alternatives
String locator
string-locator
Find and edit code or texts in your themes and plugins
HTML Editor Syntax Highlighter
html-editor-syntax-highlighter
Add syntax highlighting to WordPress code editors using CodeMirror.js
SyntaxHighlighter Evolved
syntaxhighlighter
Easily post syntax-highlighted code to your site without having to modify the code at all. As seen on WordPress.com.
Code Block Pro – Beautiful Syntax Highlighting
code-block-pro
Code highlighting powered by the VS Code engine. Performance focused. No bloat.
Enlighter – Customizable Syntax Highlighter
enlighter
All-in-one Syntax Highlighting solution. Full Gutenberg and Classic Editor integration. Graphical theme customizer. Based on EnlighterJS.
Mark New Posts Developer Profile
1 plugin · 500 total installs
How We Detect Mark New Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mark-new-posts/js/mark-new-posts.js/wp-content/plugins/mark-new-posts/css/mark-new-posts.css/wp-content/plugins/mark-new-posts/js/mark-new-posts.jsmark-new-posts/js/mark-new-posts.js?ver=mark-new-posts/css/mark-new-posts.css?ver=HTML / DOM Fingerprints
mnp-markerdata-mnp-marker-typedata-mnp-marker-textdata-mnp-marker-imagedata-mnp-marker-custom-imagedata-mnp-marker-image-widthdata-mnp-marker-image-height+3 moremnp