
Nelio Featured Posts Security & Risk Analysis
wordpress.org/plugins/nelio-featured-postsSelect the featured posts you want to show at any time and include them in your theme using a widget.
Is Nelio Featured Posts Safe to Use in 2026?
Generally Safe
Score 85/100Nelio Featured Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the 'nelio-featured-posts' plugin v2.2.4 exhibits a mixed bag of good practices and significant concerns. On the positive side, the plugin demonstrates a strong commitment to secure database interactions with 100% of its SQL queries using prepared statements, and it avoids dangerous functions, file operations, and external HTTP requests. Furthermore, the absence of recorded vulnerabilities in its history is a positive indicator of past security diligence. However, the plugin presents a considerable risk due to its large attack surface, specifically its three AJAX handlers, all of which lack authentication checks. This means any unauthenticated user can trigger these handlers, potentially leading to unintended consequences or even further exploitation if vulnerabilities exist within them. The relatively low percentage of properly escaped output (39%) also raises concerns about potential Cross-Site Scripting (XSS) vulnerabilities, which could be leveraged through the unprotected AJAX endpoints.
Despite the lack of documented CVEs, the presence of unprotected AJAX endpoints and insufficient output escaping creates a significant potential for security weaknesses. The plugin's reliance on a bundled, outdated version of Select2 (v3.5.0) is another area of concern, as older library versions can harbor known or unknown vulnerabilities. The absence of taint analysis results might simply mean no such flows were detected or the analysis was limited, but it doesn't negate the risks posed by the exposed AJAX endpoints and unescaped output. In conclusion, while the plugin has strengths in its database handling and lack of historical vulnerabilities, the unprotected AJAX handlers and inadequate output escaping are critical security weaknesses that require immediate attention. The outdated bundled library further compounds these concerns.
Key Concerns
- 3 unprotected AJAX handlers
- 39% properly escaped output
- Bundled outdated Select2 v3.5.0
- 0 Nonce checks on AJAX handlers
- 0 Capability checks on AJAX handlers
Nelio Featured Posts Security Vulnerabilities
Nelio Featured Posts Release Timeline
Nelio Featured Posts Code Analysis
Bundled Libraries
Output Escaping
Nelio Featured Posts Attack Surface
AJAX Handlers 3
WordPress Hooks 5
Maintenance & Trust
Nelio Featured Posts Maintenance & Trust
Maintenance Signals
Community Trust
Nelio Featured Posts Alternatives
Feature A Page Widget
feature-a-page-widget
A widget to display an attractive summary of any page in any widget area.
Featured Post Creative
featured-post-creative
Display Featured post on your website with 2 shortcode and 1 widget. Also work with Gutenberg shortcode block.
Relevant – Related, Featured, Latest, and Popular Posts by BestWebSoft
relevant
Add related, featured, latest, and popular posts to your WordPress website. Connect your blog readers with a relevant content.
AK Featured Post Widget
akfeatured-post-widget
A widget that you can use to display your blog posts, custom post types, or woocommerce products!
Advanced Featured Page Widget
advanced-featured-page-widget
This plugin allows you to add a featured page using a widget.
Nelio Featured Posts Developer Profile
12 plugins · 12K total installs
How We Detect Nelio Featured Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nelio-featured-posts/assets/admin/style.min.css/wp-content/plugins/nelio-featured-posts/assets/admin/lib/select2-3.5.0/select2.min.css/wp-content/plugins/nelio-featured-posts/assets/admin/post-searcher.min.css/wp-content/plugins/nelio-featured-posts/assets/admin/post-searcher.min.js/wp-content/plugins/nelio-featured-posts/assets/admin/lib/select2-3.5.0/select2.min.js/wp-content/plugins/nelio-featured-posts/includes/utils.php/wp-content/plugins/nelio-featured-posts/includes/widget.php/wp-content/plugins/nelio-featured-posts/includes/admin/settings-page.php/wp-content/plugins/nelio-featured-posts/includes/admin/ajax.php/wp-content/plugins/nelio-featured-posts/includes/admin/lib/select2-3.5.0/select2.min.js/wp-content/plugins/nelio-featured-posts/includes/admin/post-searcher.min.jsnelio-featured-posts/style.css?ver=nelio-featured-posts/script.js?ver=HTML / DOM Fingerprints
no-nelio-fpresult-contentspinneris-activehandlerdashicons-beforedashicons-menuresult-image+5 moreCopyright 2015 Nelio Software S.L.This script is distributed under the terms of the GNU General PublicLicense.This script is free software: you can redistribute it and/or modify it under+35 moredata-name="neliofp-searcher"id="neliofp-searcher"name="neliofp_settings[list_of_feat_post_ids]"id="neliofp-list-of-feat-posts"data-target="neliofp-list-of-feat-posts"data-no-results="None.<br><br><em>Add your first featured post using the selector above.</em>"+1 moreneliofp_settingsajaxurlxxxnofpneliofp_asset_link/wp-json/neliofp-rest-api/v1/posts[nelio_featured_posts]