
Newpost Catch Security & Risk Analysis
wordpress.org/plugins/newpost-catchThumbnails in new articles setting widget.
Is Newpost Catch Safe to Use in 2026?
Generally Safe
Score 91/100Newpost Catch has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of "newpost-catch" v1.3.22 indicates a generally good security posture with several positive indicators. The absence of dangerous functions, properly escaped output, and the use of prepared statements for all SQL queries are strong points. The limited attack surface, consisting of a single shortcode with no identified unprotected entry points, further contributes to this positive assessment. However, the vulnerability history presents a significant concern. The presence of one known CVE, classified as medium severity and historically related to Cross-Site Scripting (XSS), even though currently unpatched in this specific version, suggests a recurring security weakness in the plugin's development. The absence of nonce and capability checks in the code analysis, while not directly linked to an exploit in this static scan, could be potential areas for attackers to exploit if vulnerabilities were introduced in the future, especially concerning if the shortcode handles user-provided input without proper validation or authorization.
Key Concerns
- Medium severity vulnerability historically present
- Lack of nonce checks
- Lack of capability checks
Newpost Catch Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Newpost Catch <= 1.3.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via npc Shortcode
Newpost Catch Code Analysis
Output Escaping
Newpost Catch Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Newpost Catch Maintenance & Trust
Maintenance Signals
Community Trust
Newpost Catch Alternatives
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Attach Post Images
attach-post-images
Attach images to posts (independent of post content) and control post images display.
WP Carousel
wp-carousel
WP Carousel is a plugin that allows you to add a carousel with posts, categories, tags, authors, pages, and much more. It is easy to install and use.
Flickr Me
flickr-me
Add Flickr feeds to your widget ready areas.
Panoramio Images
panoramio-images
A wordpress plugin for retrieving images and values through the Panoramio API.
Newpost Catch Developer Profile
3 plugins · 11K total installs
How We Detect Newpost Catch
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/newpost-catch/no_thumb.png/wp-content/plugins/newpost-catch/style.cssHTML / DOM Fingerprints
npcatchdata-widget-id<ul id="npcatch" class="npcatch">