
Posts By Taxonomy Widget Security & Risk Analysis
wordpress.org/plugins/posts-by-taxonomy-widgetDisplay a list of taxonomy terms with recent posts in those terms in a simple to use widget
Is Posts By Taxonomy Widget Safe to Use in 2026?
Generally Safe
Score 85/100Posts By Taxonomy Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "posts-by-taxonomy-widget" plugin exhibits a generally good security posture regarding its attack surface and SQL query handling. The absence of AJAX handlers, REST API routes, shortcodes, and cron events, coupled with 100% prepared statement usage for SQL queries, significantly reduces common entry points for attacks. This suggests a conscious effort by the developers to follow secure coding practices in these areas.
However, the static analysis reveals a critical concern: the presence of the `create_function` dangerous function. This function is known to be insecure as it can be exploited for arbitrary code execution. Additionally, the low percentage of properly escaped output (38%) indicates a risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce and capability checks across all entry points further exacerbates these risks, as it means that any potential vulnerabilities could be exploited without proper authorization or verification.
The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive sign, suggesting that past versions have not had exploitable flaws. However, the static analysis findings, particularly the use of `create_function` and insufficient output escaping, present a real and present danger that could lead to future vulnerabilities. The overall security is a mixed bag, with a strong foundation in some areas but significant weaknesses in others that require immediate attention.
Key Concerns
- Use of dangerous create_function()
- Low percentage of properly escaped output
- No nonce checks found
- No capability checks found
Posts By Taxonomy Widget Security Vulnerabilities
Posts By Taxonomy Widget Code Analysis
Dangerous Functions Found
Output Escaping
Posts By Taxonomy Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Posts By Taxonomy Widget Maintenance & Trust
Maintenance Signals
Community Trust
Posts By Taxonomy Widget Alternatives
Custom Post Type Widgets
custom-post-type-widgets
Custom Post Type Widgets plugin adds default custom post type widgets.
Beautiful taxonomy filters
beautiful-taxonomy-filters
Supercharge your custom post type archives by letting visitors filter posts by their terms/categories. This plugin handles the whole thing for you!
Widget Box Lite
widget-box-lite
A toolbox of great widgets for your daily blogging. Display recent posts, social links, and much more. Designed for Theme4Press themes
Taxonomy Term Widget
taxonomy-term-widget
Add an advanced widget to your WordPress blog, like an extension of the Categories widget.
Recent Post Widget Thumbnail
recent-post-widget-thumbnail
Gives adaptable and highly organized recent posts. Show it through widget with thumbnails, post excerpt, post date.
Posts By Taxonomy Widget Developer Profile
19 plugins · 920 total installs
How We Detect Posts By Taxonomy Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/posts-by-taxonomy-widget/posts-by-taxonomy-widget.phpposts-by-taxonomy-widget/posts-by-taxonomy-widget.php?ver=HTML / DOM Fingerprints
posts-by-taxonomy-listposts-by-taxonomy-termposts-by-taxonomy-post-listid="pbtw_wrapper"name="pbtw_wrapper"