
My Featured Posts Widget Security & Risk Analysis
wordpress.org/plugins/nh-featured-postsHaving featured posts in a widget. Let's make WordPress life easier by marking any post as "Featured Post", and show 5 recent ones in t …
Is My Featured Posts Widget Safe to Use in 2026?
Generally Safe
Score 100/100My Featured Posts Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The nh-featured-posts v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. A key strength is the complete absence of critical or high-severity issues in taint analysis, alongside the fact that all SQL queries utilize prepared statements. Furthermore, the limited attack surface with no exposed AJAX handlers, REST API routes, or shortcodes is a positive indicator. The presence of nonce and capability checks, though only one of each is detected, also suggests some consideration for security. However, the primary concern lies in the insufficient output escaping, with only 36% of outputs being properly escaped. This could leave the plugin vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is not sufficiently sanitized before being displayed. The lack of any recorded vulnerabilities in its history is encouraging, but this is a single version's analysis, and a comprehensive assessment would involve historical code reviews and further version testing. The single external HTTP request also warrants a closer look to ensure it is handled securely and doesn't introduce further risks.
Key Concerns
- Insufficient output escaping detected
- Presence of external HTTP request
My Featured Posts Widget Security Vulnerabilities
My Featured Posts Widget Code Analysis
Output Escaping
My Featured Posts Widget Attack Surface
WordPress Hooks 4
Maintenance & Trust
My Featured Posts Widget Maintenance & Trust
Maintenance Signals
Community Trust
My Featured Posts Widget Alternatives
Category Posts Widget
category-posts
Adds a widget that shows the most recent posts from a single category.
Bulk Move
bulk-move
Move or remove posts in bulk from one category, tag or custom taxonomy to another.
Advance Product Search & Ajax Search for WooCommerce
th-advance-product-search
Upgrade WooCommerce search with fast Ajax product search, live results, and category-based search. Help customers find products instantly.
Blog Filter Post Filtering
blog-filter
Blog Filter helps users display posts in filterable grid and masonry layouts. Organize content by categories or tags with customizable designs.
ReOrder Posts within Categories
reorder-post-within-categories
Enables manual ranking of post (and custom post) within taxonomy terms using a drag & drop grid interface.
My Featured Posts Widget Developer Profile
1 plugin · 0 total installs
How We Detect My Featured Posts Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
/wp-json/wp/v2/posts?_featured_post=1&orderby=date&order=desc&per_page=5