MediaPress Featured Content Security & Risk Analysis

wordpress.org/plugins/mpp-featured-content

Let your users show their featured photos(or audio, video, doc) and featured galleries on their BuddyPress profile.

60 active installs v1.0.2 PHP 5.3.0+ WP 4.6+ Updated Aug 7, 2023
buddypressbuddypress-gallerymediapressuser-featured-gallery
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MediaPress Featured Content Safe to Use in 2026?

Generally Safe

Score 85/100

MediaPress Featured Content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "mpp-featured-content" v1.0.2 plugin exhibits a generally good security posture, largely due to its limited attack surface and the absence of known vulnerabilities. The plugin correctly utilizes prepared statements for all SQL queries, preventing SQL injection risks. It also implements a nonce check and has zero file operations or external HTTP requests, which are positive indicators. However, a significant concern lies in the low percentage of properly escaped output (39%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied or dynamic data is likely being rendered without adequate sanitization, allowing attackers to inject malicious scripts.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

MediaPress Featured Content Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MediaPress Featured Content Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
54
35 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

39% escaped89 total outputs
Attack Surface

MediaPress Featured Content Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_mppftc_featured_actioncore\class-mppftc-ajax-handler.php:29
WordPress Hooks 21
actionmpp_admin_register_settingsadmin\class-mppftc-admin-helper.php:22
actionmpp_setup_navcore\class-mppftc-action-handler.php:29
actionmpp_group_navcore\class-mppftc-action-handler.php:30
actionmpp_setup_globalscore\class-mppftc-action-handler.php:31
filtermpp_groups_gallery_located_templatecore\class-mppftc-action-handler.php:33
filtermpp_shortcode_list_gallery_defaultscore\class-mppftc-shortcode-extender.php:32
filtermpp_shortcode_list_gallery_query_argscore\class-mppftc-shortcode-extender.php:33
filtermpp_shortcode_list_media_defaultscore\class-mppftc-shortcode-extender.php:36
filtermpp_shortcode_list_media_query_argscore\class-mppftc-shortcode-extender.php:37
actionmpp_media_metacore\class-mppftc-view-helper.php:30
actionmpp_lightbox_media_action_before_linkcore\class-mppftc-view-helper.php:31
actionmpp_gallery_metacore\class-mppftc-view-helper.php:32
actionbp_profile_header_metacore\class-mppftc-view-helper.php:35
actionbp_group_header_metacore\class-mppftc-view-helper.php:36
actionbp_template_contentcore\mppftc-templates.php:138
actionbp_template_contentcore\mppftc-templates.php:153
actionmpp_widgets_initcore\widgets\class-mppftc-gallery-widget.php:287
actionmpp_widgets_initcore\widgets\class-mppftc-media-widget.php:252
actionmpp_loadedmpp-featured-content.php:78
actionmpp_enqueue_scriptsmpp-featured-content.php:79
actionmpp_initmpp-featured-content.php:80
Maintenance & Trust

MediaPress Featured Content Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedAug 7, 2023
PHP min version5.3.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

MediaPress Featured Content Developer Profile

Brajesh Singh

12 plugins · 2K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
3856 days
View full developer profile
Detection Fingerprints

How We Detect MediaPress Featured Content

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mpp-featured-content/assets/css/mpp-featured-content.css/wp-content/plugins/mpp-featured-content/assets/js/mpp-featured-content.js
Script Paths
/wp-content/plugins/mpp-featured-content/assets/js/mpp-featured-content.js
Version Parameters
mpp-featured-content/assets/css/mpp-featured-content.css?ver=mpp-featured-content/assets/js/mpp-featured-content.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-nonce
JS Globals
MPPFeaturedContent
Shortcode Output
[mpp-list-gallery featured][mpp-list-media featured]
FAQ

Frequently Asked Questions about MediaPress Featured Content