
Popular Posts by Webline Security & Risk Analysis
wordpress.org/plugins/popular-posts-by-weblinePopular Posts will display the posts according to the filters applied from widget settings.
Is Popular Posts by Webline Safe to Use in 2026?
Mostly Safe
Score 70/100Popular Posts by Webline is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "popular-posts-by-webline" plugin v1.1.1 exhibits a mixed security posture. While the static analysis shows a small attack surface with no apparent unprotected entry points and the absence of dangerous functions or raw SQL queries, several concerns are highlighted. A significant portion (48%) of output escaping is missing, which, coupled with zero nonce checks and zero capability checks for the identified shortcode, presents a potential risk for cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is not properly sanitized before rendering.
The vulnerability history is a major red flag. The presence of one known medium-severity CVE, which is currently unpatched, indicates a direct, confirmed security flaw that users of this version are exposed to. The common vulnerability type being Cross-site Scripting further corroborates the concerns raised by the static analysis regarding insufficient output escaping. The fact that the last vulnerability was in the future (2025-09-27) is likely an artifact of the data and should be treated as a recent or ongoing vulnerability.
In conclusion, while the plugin has some good practices like using prepared statements for SQL and a limited attack surface, the lack of robust output escaping, absence of security checks on its single shortcode, and critically, the existence of an unpatched medium-severity XSS vulnerability, make this version a moderate to high risk. Users should prioritize updating to a patched version or disabling the plugin until the vulnerability is addressed.
Key Concerns
- Unpatched CVE (medium severity)
- Significant portion of output unescaped
- No nonce checks on shortcode
- No capability checks on shortcode
Popular Posts by Webline Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Popular Posts by Webline <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Popular Posts by Webline Code Analysis
Output Escaping
Popular Posts by Webline Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Popular Posts by Webline Maintenance & Trust
Maintenance Signals
Community Trust
Popular Posts by Webline Alternatives
WebberZone Top 10 — Popular Posts
top-10
Track post views and page views, and display popular posts and trending content on your WordPress site.
WP Most Popular
wp-most-popular
WP Most Popular is a simple plugin which tracks your most popular blog posts based on views and lets you display them in your theme or blog sidebar.
KR Popular Posts
knowledgering-post-popularity-graph-tool
KR Popular Posts shows graph of a posts popularity percentage. Popularity based on post views, comments, ratings, retweets and facebook likes ( popula …
Launchpad Popular Posts
launchpad-popular-posts
This is a very simple, easy to use plugin which creates a widget that can be used to display Popular Posts, Related Posts, Featured Posts, Recent Post …
Featured Posts Widget
olympus-featured-posts-widget
Add a selection of posts to your sidebar or another widget location.
Popular Posts by Webline Developer Profile
13 plugins · 5K total installs
How We Detect Popular Posts by Webline
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/popular-posts-by-webline/admin/assets/css/admin-style.css/wp-content/plugins/popular-posts-by-webline/admin/assets/js/popular-posts-by-webline-admin.js/wp-content/plugins/popular-posts-by-webline/public/css/style.css/wp-content/plugins/popular-posts-by-webline/admin/assets/js/popular-posts-by-webline-admin.jspopular-posts-by-webline/admin/assets/css/admin-style.css?ver=popular-posts-by-webline/admin/assets/js/popular-posts-by-webline-admin.js?ver=popular-posts-by-webline/public/css/style.css?ver=HTML / DOM Fingerprints
wli-popular-posts-widget<!-- wli_popular_posts Shortcode -->data-post-typedata-posts-countdata-thumb-sizedata-show-datedata-show-commentdata-show-author+5 moreWLIPP_ScriptsData[wli_popular_posts]