
NS Featured Posts Security & Risk Analysis
wordpress.org/plugins/ns-featured-postsA plugin for making posts, pages, or custom post types featured. Users can enable/disable Featured flags for selected post types.
Is NS Featured Posts Safe to Use in 2026?
Generally Safe
Score 100/100NS Featured Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'ns-featured-posts' plugin v3.0.1 exhibits a mixed security posture. While it demonstrates good practices in terms of output escaping and avoids dangerous functions or file operations, several critical areas raise concerns. The presence of two unprotected AJAX handlers significantly expands the attack surface without proper authentication or authorization checks, which is a common vector for exploitation. Although no specific critical or high-severity taint flows were identified in this analysis, the single unsanitized path flow warrants attention as it could potentially lead to vulnerabilities if exploited in conjunction with other factors.
The plugin's vulnerability history is currently clean, with no recorded CVEs. This is a positive indicator, suggesting that the developers may be responsive to security or that past issues have been effectively addressed. However, a lack of past vulnerabilities does not guarantee future security, especially in light of the identified unprotected entry points. The plugin's strengths lie in its robust output escaping and absence of dangerous code patterns. The primary weaknesses are the unprotected AJAX handlers, which represent a direct risk that needs immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized path flow
- SQL queries without prepared statements
NS Featured Posts Security Vulnerabilities
NS Featured Posts Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
NS Featured Posts Attack Surface
AJAX Handlers 3
WordPress Hooks 16
Maintenance & Trust
NS Featured Posts Maintenance & Trust
Maintenance Signals
Community Trust
NS Featured Posts Alternatives
Genesis Featured Widget Amplified
genesis-featured-widget-amplified
Genesis Featured Posts with support for custom post types, taxonomies, and so much more
Featured Post
featured-post
Featured Post Plugin for Wordpress.
CodeFlavors Featured Post
codeflavors-featured-post
Featured Post Plugin for WordPress with custom post type support.
Featured Custom Posts Widget
featured-custom-posts-widget
Widget that allows custom post types and taxonomies to be displayed. Works well with Custom Post Type UI and Taxonomy Images plugins.
WP Featured News – Custom Posts Listing Elements
wp-featured-news-custom-posts-listing-elements
WP Featured News plugin allows you to display your posts anywhere of your web-pages with 10 powerful and creatively designed post blocks.
NS Featured Posts Developer Profile
9 plugins · 9K total installs
How We Detect NS Featured Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ns-featured-posts/assets/css/ns-featured-posts.css/wp-content/plugins/ns-featured-posts/assets/js/ns-featured-posts.js/wp-content/plugins/ns-featured-posts/assets/css/ns-featured-posts-widget.css/wp-content/plugins/ns-featured-posts/assets/js/ns-featured-posts-widget.js/wp-content/plugins/ns-featured-posts/assets/js/nsfp-featured-posts-admin.js/wp-content/plugins/ns-featured-posts/assets/js/nsfp-featured-posts-widget.js/wp-content/plugins/ns-featured-posts/assets/js/ns-featured-posts.js/wp-content/plugins/ns-featured-posts/assets/js/ns-featured-posts-widget.js/wp-content/plugins/ns-featured-posts/assets/js/nsfp-featured-posts-admin.js/wp-content/plugins/ns-featured-posts/assets/js/nsfp-featured-posts-widget.jsns-featured-posts/assets/css/ns-featured-posts.css?ver=ns-featured-posts/assets/js/ns-featured-posts.js?ver=ns-featured-posts/assets/css/ns-featured-posts-widget.css?ver=ns-featured-posts/assets/js/ns-featured-posts-widget.js?ver=ns-featured-posts/assets/js/nsfp-featured-posts-admin.js?ver=ns-featured-posts/assets/js/nsfp-featured-posts-widget.js?ver=HTML / DOM Fingerprints
nsfp-featured-postsnsfp-wrappernsfp-slidernsfp-contentnsfp-titlensfp-excerptnsfp-thumbnailnsfp-meta+26 more<!-- NS Featured Posts Widget -->data-nsfp-post-iddata-nsfp-featured-statusdata-nsfp-toggle-noncedata-nsfp-noncedata-nsfp-post-typensfp_featured_posts_paramsnsfp_widget_params/wp-json/nsfp/v1/featured-toggle/wp-json/nsfp/v1/get-posts[ns_featured_posts]