
Other Posts Security & Risk Analysis
wordpress.org/plugins/other-postsDisplays related posts after each blog posts finding them with the full text search feature of MySQL.
Is Other Posts Safe to Use in 2026?
Generally Safe
Score 100/100Other Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'other-posts' plugin v1.3.0 exhibits a strong security posture in terms of its attack surface and vulnerability history. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with exploitable entry points is a significant positive. Furthermore, the lack of any known CVEs, historical or current, suggests a well-maintained and secure codebase. The taint analysis revealing no critical or high severity flows with unsanitized paths further reinforces this positive assessment. The plugin also demonstrates good practices by including nonce checks and a reasonable proportion of SQL queries using prepared statements.
However, a significant concern arises from the complete lack of output escaping for all identified output points. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or data processed by the plugin could be rendered directly in the browser without proper sanitization, allowing attackers to inject malicious scripts. The complete absence of capability checks is also a weakness, potentially allowing unauthorized users to perform actions they shouldn't, although the limited attack surface mitigates this risk to some extent.
In conclusion, while the plugin excels in minimizing its attack surface and has a clean vulnerability history, the critical oversight in output escaping presents a substantial security risk. The absence of capability checks is a secondary concern that should be addressed. The plugin's strengths lie in its low attack surface and clean history, but the unescaped output is a major flaw that needs immediate attention.
Key Concerns
- 100% of outputs are unescaped
- 0 capability checks
Other Posts Security Vulnerabilities
Other Posts Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Other Posts Attack Surface
WordPress Hooks 4
Maintenance & Trust
Other Posts Maintenance & Trust
Maintenance Signals
Community Trust
Other Posts Alternatives
Inline Related Posts
intelly-related-posts
Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
YARPP – Yet Another Related Posts Plugin
yet-another-related-posts-plugin
The best WordPress plugin for displaying related posts. Simple and flexible, with a powerful proven algorithm and inbuilt caching.
Contextual Related Posts
contextual-related-posts
Keep visitors on your site longer with intelligent, fast-loading, contextually related posts. Block, shortcode, custom post type and widget ready.
Related Posts for WordPress
related-posts-for-wp
The best WordPress plugin for related posts. Simple, flexible, powerful algorithm, and built-in caching. Fully setup with only 1 click!
Other Posts Developer Profile
14 plugins · 515K total installs
How We Detect Other Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/other-posts/images/empty.gifHTML / DOM Fingerprints
opost-itemopost-titleopost-imageopost-excerptopost-horizontaldata-post-id<div class="opost-item"><div class="opost-image"><a href="{link}"><img src="{image}"></a></div><div class="opost-title"><a href="{link}">{title}</a></div><div class="opost-excerpt">{excerpt}</div><div style="clear:both"></div></div>