
Nelio Related Posts Security & Risk Analysis
wordpress.org/plugins/nelio-related-postsGet a list of Related Posts by querying your Swiftype account, or using WordPress' regular search functions.
Is Nelio Related Posts Safe to Use in 2026?
Generally Safe
Score 100/100Nelio Related Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nelio-related-posts" v2.1.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerabilities (CVEs) in its history. This suggests a generally stable and well-maintained codebase.
However, significant concerns arise from the static analysis. The plugin has a single entry point via an AJAX handler that lacks any authentication checks. This is a critical vulnerability as it allows unauthenticated users to potentially interact with sensitive plugin functionality, leading to unauthorized actions or information disclosure. Furthermore, a notable percentage of its output (71%) is not properly escaped. While taint analysis shows no specific flaws, this lack of proper output escaping on a substantial portion of its outputs is a high-risk indicator for potential Cross-Site Scripting (XSS) vulnerabilities.
In conclusion, while the absence of historical vulnerabilities and secure SQL practices are strengths, the presence of an unprotected AJAX endpoint and widespread unescaped output significantly elevates the risk profile of this plugin. These issues require immediate attention to secure the plugin effectively.
Key Concerns
- AJAX handler without authentication checks
- High percentage of unescaped output
Nelio Related Posts Security Vulnerabilities
Nelio Related Posts Code Analysis
Output Escaping
Nelio Related Posts Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
Nelio Related Posts Maintenance & Trust
Maintenance Signals
Community Trust
Nelio Related Posts Alternatives
ElasticPress
elasticpress
A fast and flexible search and query engine for WordPress.
Init Live Search – AI-Powered, Related Posts, Slash Commands
init-live-search
Fast, modern live search powered by REST API — with AI-powered Related Posts Engine, slash commands, SEO-aware, ACF, Woo, and custom UI presets.
Assign Related Posts
assign-related-posts
Assigns related posts to specific post.
FV Swiftype
fv-swiftype
Use Swiftype external crawler engine for your search.
Google related post links
google-related-post-links
Displays a list of related posts and searches by Google
Nelio Related Posts Developer Profile
12 plugins · 11K total installs
How We Detect Nelio Related Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nelio-related-posts/assets/nelio-srp.cssnelio-srp.css?ver=HTML / DOM Fingerprints
neliosrp-rowneliosrpdata-swiftype-index