
Now Featuring WordPress Widget Security & Risk Analysis
wordpress.org/plugins/now-featuringThe Now Featuring Wordpress Widget allows you to showcase featured content from your posts or pages on your sidebar in multiple ways.
Is Now Featuring WordPress Widget Safe to Use in 2026?
Generally Safe
Score 85/100Now Featuring WordPress Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "now-featuring" plugin v0.8 exhibits a generally good security posture with no recorded vulnerabilities and a limited attack surface. The absence of dangerous functions, SQL queries, file operations, and external HTTP requests is a positive indicator. However, a significant concern arises from the complete lack of output escaping. With 58 outputs identified and 0% properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied input that is reflected in the output without proper sanitization can be exploited by attackers to inject malicious scripts. Additionally, the absence of nonce and capability checks, while currently mitigated by having no unprotected entry points, leaves the plugin vulnerable if new entry points are introduced or existing ones are inadvertently exposed without proper authorization mechanisms in place.
The plugin's clean vulnerability history is a strength, suggesting the developers have a good understanding of secure coding practices in the past. However, the current static analysis findings, particularly the unescaped output, represent a significant weakness that requires immediate attention. Without addressing the output escaping issue, the plugin remains susceptible to common web attacks, despite its otherwise clean record and limited attack surface.
Key Concerns
- 0% output escaping
- 0 nonce checks
- 0 capability checks
Now Featuring WordPress Widget Security Vulnerabilities
Now Featuring WordPress Widget Code Analysis
Output Escaping
Now Featuring WordPress Widget Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Now Featuring WordPress Widget Maintenance & Trust
Maintenance Signals
Community Trust
Now Featuring WordPress Widget Alternatives
Product Gallery Slider, Additional Variation Images, Product Video, Product Image Zoom and Lightbox for WooCommerce – WooGallery
gallery-slider-for-woocommerce
🔥 All-in-One WooCommerce Product Image and Video Gallery Solution to Enhance Your Customers' Shopping Experience and Boost Sales Instantly! 🚀
Product Slider and Carousel with Category for WooCommerce
woo-product-slider-and-carousel-with-category
WooCommerce Product, Best Selling Product, Featured Product Slider/Carousel with category. Also work with Gutenberg shortcode block.
Feature A Page Widget
feature-a-page-widget
A widget to display an attractive summary of any page in any widget area.
WP Featured Content and Slider
wp-featured-content-and-slider
A quick, easy way to add and display what features your company, product or service offers, using our shortcode OR template code or Gutenberg block.
Widget Builder
widget-builder
Widget Builder uses native WordPress editing interface to provide a unique tool to build custom widgets for your site(s).
Now Featuring WordPress Widget Developer Profile
1 plugin · 10 total installs
How We Detect Now Featuring WordPress Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/now-featuring/assets/css/now_featuring.css/wp-content/plugins/now-featuring/assets/js/now_featuring.js/wp-content/plugins/now-featuring/assets/css/nf_admin.css/wp-content/plugins/now-featuring/assets/js/nf_admin.jsnow_featuring.css?ver=now_featuring.js?ver=HTML / DOM Fingerprints
[now_featuring]