Most And Least Read Posts Widget Security & Risk Analysis

wordpress.org/plugins/most-and-least-read-posts-widget

Provide two widgets, showing lists of the most and reast read posts.

1K active installs v2.5.21 PHP 7.0+ WP 2.9+ Updated Apr 11, 2025
least-readmost-readpopular-postspostposts
96
A · Safe
CVEs total3
Unpatched0
Last CVEApr 16, 2025
Safety Verdict

Is Most And Least Read Posts Widget Safe to Use in 2026?

Generally Safe

Score 96/100

Most And Least Read Posts Widget has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Apr 16, 2025Updated 11mo ago
Risk Assessment

The "most-and-least-read-posts-widget" plugin v2.5.21 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks for its entry points, which is commendable. There are no identified critical or high severity taint flows, nor any instances of dangerous function usage or file operations, suggesting a generally cautious approach to potentially risky code. However, a significant concern arises from the vulnerability history, which shows 3 known CVEs, including one high severity and two medium severity vulnerabilities. The types of past vulnerabilities (XSS, CSRF, SQL Injection) are common and serious, and the recency of the last vulnerability (April 2025) indicates a need for ongoing vigilance and prompt patching. Furthermore, the low percentage of properly escaped output (20%) is a substantial weakness, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities, especially if input from any of the entry points is not rigorously handled downstream. The plugin's strengths lie in its use of secure coding practices for database interactions and entry point authentication. Its primary weaknesses are its historical vulnerability record and the significant lack of output escaping.

Key Concerns

  • Significant number of unpatched or historical vulnerabilities
  • Low percentage of properly escaped output (20%)
Vulnerabilities
3

Most And Least Read Posts Widget Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
2

3 total CVEs

CVE-2025-39549medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Most And Least Read Posts Widget <= 2.5.20 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 16, 2025 Patched in 2.5.21 (6d)
CVE-2024-49628medium · 4.3Cross-Site Request Forgery (CSRF)

Most And Least Read Posts Widget <= 2.5.18 - Cross-Site Request Forgery via most_and_least_read_posts_options

Oct 18, 2024 Patched in 2.5.19 (6d)
CVE-2023-52133high · 8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Most And Least Read Posts Widget <=2.5.16 - Authenticated(Contributor+) SQL Injection via Widget settings

Dec 28, 2023 Patched in 2.5.17 (26d)
Code Analysis
Analyzed Mar 16, 2026

Most And Least Read Posts Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
74
18 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

20% escaped92 total outputs
Attack Surface

Most And Least Read Posts Widget Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[most_read_posts] most_and_least_read_posts.php:752
WordPress Hooks 8
actionplugins_loadedmost_and_least_read_posts.php:22
filterthe_contentmost_and_least_read_posts.php:24
filterplugin_action_linksmost_and_least_read_posts.php:26
actionadmin_menumost_and_least_read_posts.php:27
filtermanage_posts_columnsmost_and_least_read_posts.php:29
actionmanage_posts_custom_columnmost_and_least_read_posts.php:30
actionwidgets_initmost_and_least_read_posts.php:745
actionwidgets_initmost_and_least_read_posts.php:748
Maintenance & Trust

Most And Least Read Posts Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 11, 2025
PHP min version7.0
Downloads93K

Community Trust

Rating100/100
Number of ratings6
Active installs1K
Developer Profile

Most And Least Read Posts Widget Developer Profile

whiletrue

7 plugins · 3K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
13 days
View full developer profile
Detection Fingerprints

How We Detect Most And Least Read Posts Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Most And Least Read Posts Widget