Nelio Related Posts Security & Risk Analysis

wordpress.org/plugins/nelio-related-posts

Get a list of Related Posts by querying your Swiftype account, or using WordPress' regular search functions.

10 active installs v2.1.1 PHP + WP 3.3+ Updated Unknown
cachedrelated-postsearchswiftype
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Nelio Related Posts Safe to Use in 2026?

Generally Safe

Score 100/100

Nelio Related Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "nelio-related-posts" v2.1.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerabilities (CVEs) in its history. This suggests a generally stable and well-maintained codebase.

However, significant concerns arise from the static analysis. The plugin has a single entry point via an AJAX handler that lacks any authentication checks. This is a critical vulnerability as it allows unauthenticated users to potentially interact with sensitive plugin functionality, leading to unauthorized actions or information disclosure. Furthermore, a notable percentage of its output (71%) is not properly escaped. While taint analysis shows no specific flaws, this lack of proper output escaping on a substantial portion of its outputs is a high-risk indicator for potential Cross-Site Scripting (XSS) vulnerabilities.

In conclusion, while the absence of historical vulnerabilities and secure SQL practices are strengths, the presence of an unprotected AJAX endpoint and widespread unescaped output significantly elevates the risk profile of this plugin. These issues require immediate attention to secure the plugin effectively.

Key Concerns

  • AJAX handler without authentication checks
  • High percentage of unescaped output
Vulnerabilities
None known

Nelio Related Posts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Nelio Related Posts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
34
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped48 total outputs
Attack Surface
1 unprotected

Nelio Related Posts Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_nelioab_campaign_dismiss_noticeincludes\admin\nelioab-campaign.php:5
WordPress Hooks 9
actionadd_meta_boxesincludes\admin\edit-post.php:3
actionsave_postincludes\admin\edit-post.php:24
actionadmin_noticesincludes\admin\nelioab-campaign.php:14
actionadmin_menuincludes\admin\settings-page.php:13
actionadmin_initincludes\admin\settings-page.php:14
actionwp_enqueue_scriptsincludes\nelio-srp-main.php:13
actionsave_postincludes\nelio-srp-main.php:16
actionwidgets_initincludes\widget.php:76
actionplugins_loadedmain.php:47
Maintenance & Trust

Nelio Related Posts Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating80/100
Number of ratings1
Active installs10
Developer Profile

Nelio Related Posts Developer Profile

Nelio Software

12 plugins · 11K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
957 days
View full developer profile
Detection Fingerprints

How We Detect Nelio Related Posts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nelio-related-posts/assets/nelio-srp.css
Version Parameters
nelio-srp.css?ver=

HTML / DOM Fingerprints

CSS Classes
neliosrp-rowneliosrp
Data Attributes
data-swiftype-index
FAQ

Frequently Asked Questions about Nelio Related Posts