Popular Posts by Webline Security & Risk Analysis

wordpress.org/plugins/popular-posts-by-webline

Popular Posts will display the posts according to the filters applied from widget settings.

1K active installs v1.1.1 PHP + WP 3.2+ Updated Dec 10, 2024
popularpopular-contentpopular-postspopular-posts-widgetposts
70
B · Generally Safe
CVEs total1
Unpatched1
Last CVESep 27, 2025
Safety Verdict

Is Popular Posts by Webline Safe to Use in 2026?

Mostly Safe

Score 70/100

Popular Posts by Webline is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Sep 27, 2025Updated 1yr ago
Risk Assessment

The "popular-posts-by-webline" plugin v1.1.1 exhibits a mixed security posture. While the static analysis shows a small attack surface with no apparent unprotected entry points and the absence of dangerous functions or raw SQL queries, several concerns are highlighted. A significant portion (48%) of output escaping is missing, which, coupled with zero nonce checks and zero capability checks for the identified shortcode, presents a potential risk for cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is not properly sanitized before rendering.

The vulnerability history is a major red flag. The presence of one known medium-severity CVE, which is currently unpatched, indicates a direct, confirmed security flaw that users of this version are exposed to. The common vulnerability type being Cross-site Scripting further corroborates the concerns raised by the static analysis regarding insufficient output escaping. The fact that the last vulnerability was in the future (2025-09-27) is likely an artifact of the data and should be treated as a recent or ongoing vulnerability.

In conclusion, while the plugin has some good practices like using prepared statements for SQL and a limited attack surface, the lack of robust output escaping, absence of security checks on its single shortcode, and critically, the existence of an unpatched medium-severity XSS vulnerability, make this version a moderate to high risk. Users should prioritize updating to a patched version or disabling the plugin until the vulnerability is addressed.

Key Concerns

  • Unpatched CVE (medium severity)
  • Significant portion of output unescaped
  • No nonce checks on shortcode
  • No capability checks on shortcode
Vulnerabilities
1

Popular Posts by Webline Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62900medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Popular Posts by Webline <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 27, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Popular Posts by Webline Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
125
133 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

52% escaped258 total outputs
Attack Surface

Popular Posts by Webline Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wli_popular_posts] admin\class\hook.php:36
WordPress Hooks 11
actionadmin_initadmin\class\hook.php:17
actionupgrader_process_completeadmin\class\hook.php:24
actionadmin_enqueue_scriptsadmin\class\hook.php:27
actionwp_enqueue_scriptsadmin\class\hook.php:30
actionadmin_menuadmin\class\hook.php:33
actionadmin_headadmin\class\hook.php:53
filteradmin_footer_textadmin\class\hook.php:57
filterpre_set_site_transient_update_pluginsadmin\class\hook.php:59
actionwidgets_initadmin\class\popular-posts.php:467
actionwp_headadmin\class\popular-posts.php:468
actionplugins_loadedpopularposts-by-webline.php:34
Maintenance & Trust

Popular Posts by Webline Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 10, 2024
PHP min version
Downloads29K

Community Trust

Rating88/100
Number of ratings8
Active installs1K
Developer Profile

Popular Posts by Webline Developer Profile

WeblineIndia

13 plugins · 5K total installs

82
trust score
Avg Security Score
91/100
Avg Patch Time
54 days
View full developer profile
Detection Fingerprints

How We Detect Popular Posts by Webline

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/popular-posts-by-webline/admin/assets/css/admin-style.css/wp-content/plugins/popular-posts-by-webline/admin/assets/js/popular-posts-by-webline-admin.js/wp-content/plugins/popular-posts-by-webline/public/css/style.css
Script Paths
/wp-content/plugins/popular-posts-by-webline/admin/assets/js/popular-posts-by-webline-admin.js
Version Parameters
popular-posts-by-webline/admin/assets/css/admin-style.css?ver=popular-posts-by-webline/admin/assets/js/popular-posts-by-webline-admin.js?ver=popular-posts-by-webline/public/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wli-popular-posts-widget
HTML Comments
<!-- wli_popular_posts Shortcode -->
Data Attributes
data-post-typedata-posts-countdata-thumb-sizedata-show-datedata-show-commentdata-show-author+5 more
JS Globals
WLIPP_ScriptsData
Shortcode Output
[wli_popular_posts]
FAQ

Frequently Asked Questions about Popular Posts by Webline