El mejor Cluster Security & Risk Analysis

wordpress.org/plugins/mejorcluster

Create easy related posts blocks with a simple shortcode. This plugin is light, very easy to use and designed for SEO.

100 active installs v1.1.16 PHP 8.0+ WP 4.7+ Updated Dec 2, 2024
related-postsseo
91
A · Safe
CVEs total1
Unpatched0
Last CVEOct 14, 2024
Safety Verdict

Is El mejor Cluster Safe to Use in 2026?

Generally Safe

Score 91/100

El mejor Cluster has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 14, 2024Updated 1yr ago
Risk Assessment

The 'mejorcluster' plugin version 1.1.16 presents a generally good security posture with several positive indicators. The static analysis reveals no identified dangerous functions, no direct SQL queries, and a high percentage of properly escaped output. Furthermore, the presence of nonce and capability checks suggests a conscious effort towards securing sensitive operations. The absence of any taint analysis findings and the fact that all known vulnerabilities are patched are significant strengths.

However, a deeper examination reveals potential areas for improvement. The presence of one known medium-severity vulnerability in the past, specifically Cross-Site Scripting, even though currently patched, warrants attention. This indicates that input validation and output escaping are areas that have historically required attention. While the current version shows good escaping, the past incident highlights a potential for future similar issues if not diligently maintained. The limited attack surface with only one shortcode entry point is a positive, but it's crucial that this shortcode is robustly secured against any unforeseen input handling issues.

In conclusion, 'mejorcluster' v1.1.16 exhibits strong security fundamentals with robust coding practices observed in the static analysis. The plugin's history, while including a past medium-severity XSS, is positive due to the current patching status. The main area of focus should remain on continued vigilance regarding input sanitization and output escaping, especially concerning the identified shortcode, to prevent any recurrence of historical vulnerability types.

Key Concerns

  • Past medium severity vulnerability
  • Potential for unescaped output on remaining 17% of outputs
Vulnerabilities
1

El mejor Cluster Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-49232medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

El mejor Cluster <= 1.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 14, 2024 Patched in 1.1.16 (53d)
Code Analysis
Analyzed Mar 16, 2026

El mejor Cluster Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
24 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped29 total outputs
Attack Surface

El mejor Cluster Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mejorcluster] includes\class-mejorcluster.php:177
WordPress Hooks 9
actionplugins_loadedincludes\class-mejorcluster.php:142
actionadmin_enqueue_scriptsincludes\class-mejorcluster.php:156
actionadmin_enqueue_scriptsincludes\class-mejorcluster.php:157
actionadd_meta_boxesincludes\class-mejorcluster.php:158
actionsave_postincludes\class-mejorcluster.php:159
actionadmin_menuincludes\class-mejorcluster.php:160
actionadmin_initincludes\class-mejorcluster.php:161
actionwp_enqueue_scriptsincludes\class-mejorcluster.php:175
actionwp_enqueue_scriptsincludes\class-mejorcluster.php:176
Maintenance & Trust

El mejor Cluster Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedDec 2, 2024
PHP min version8.0
Downloads7K

Community Trust

Rating78/100
Number of ratings7
Active installs100
Developer Profile

El mejor Cluster Developer Profile

derethor

1 plugin · 100 total installs

82
trust score
Avg Security Score
91/100
Avg Patch Time
53 days
View full developer profile
Detection Fingerprints

How We Detect El mejor Cluster

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mejorcluster/admin/css/mejorcluster-admin.css/wp-content/plugins/mejorcluster/admin/js/mejorcluster-admin.js
Script Paths
/wp-content/plugins/mejorcluster/admin/js/mejorcluster-admin.js
Version Parameters
mejorcluster-admin.css?ver=mejorcluster-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
mejorcluster-metabox-noncemejorcluster-titlemejorcluster-descmejorcluster-imagemejorcluster-image-previewmejorcluster-image-button
FAQ

Frequently Asked Questions about El mejor Cluster