Newpost Catch Security & Risk Analysis

wordpress.org/plugins/newpost-catch

Thumbnails in new articles setting widget.

10K active installs v1.3.22 PHP 7.2+ WP 5.6+ Updated Mar 3, 2025
imageimagespostssidebarwidget
91
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 20, 2025
Safety Verdict

Is Newpost Catch Safe to Use in 2026?

Generally Safe

Score 91/100

Newpost Catch has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 20, 2025Updated 1yr ago
Risk Assessment

The static analysis of "newpost-catch" v1.3.22 indicates a generally good security posture with several positive indicators. The absence of dangerous functions, properly escaped output, and the use of prepared statements for all SQL queries are strong points. The limited attack surface, consisting of a single shortcode with no identified unprotected entry points, further contributes to this positive assessment. However, the vulnerability history presents a significant concern. The presence of one known CVE, classified as medium severity and historically related to Cross-Site Scripting (XSS), even though currently unpatched in this specific version, suggests a recurring security weakness in the plugin's development. The absence of nonce and capability checks in the code analysis, while not directly linked to an exploit in this static scan, could be potential areas for attackers to exploit if vulnerabilities were introduced in the future, especially concerning if the shortcode handles user-provided input without proper validation or authorization.

Key Concerns

  • Medium severity vulnerability historically present
  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
1

Newpost Catch Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-1406medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Newpost Catch <= 1.3.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via npc Shortcode

Feb 20, 2025 Patched in 1.3.20 (21d)
Code Analysis
Analyzed Mar 16, 2026

Newpost Catch Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
104 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped104 total outputs
Attack Surface

Newpost Catch Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[npc] class.php:286
WordPress Hooks 3
actionwp_enqueue_scriptsclass.php:25
actioninitclass.php:28
actionwidgets_initnewpost-catch.php:18
Maintenance & Trust

Newpost Catch Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 3, 2025
PHP min version7.2
Downloads288K

Community Trust

Rating100/100
Number of ratings2
Active installs10K
Developer Profile

Newpost Catch Developer Profile

Tetsuya Imamura

3 plugins · 11K total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
21 days
View full developer profile
Detection Fingerprints

How We Detect Newpost Catch

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/newpost-catch/no_thumb.png
Script Paths
/wp-content/plugins/newpost-catch/style.css

HTML / DOM Fingerprints

CSS Classes
npcatch
Data Attributes
data-widget-id
Shortcode Output
<ul id="npcatch" class="npcatch">
FAQ

Frequently Asked Questions about Newpost Catch