
Posts of Current Category Security & Risk Analysis
wordpress.org/plugins/posts-of-current-categoryDisplay or List post name of current category.
Is Posts of Current Category Safe to Use in 2026?
Generally Safe
Score 85/100Posts of Current Category has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "posts-of-current-category" plugin v0.4 presents a mixed security picture. On the positive side, it boasts zero known vulnerabilities, a clean vulnerability history, and a seemingly limited attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events directly exposed without authentication. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are excellent security practices.
However, there are significant concerns within the code. The presence of the `create_function` is a major red flag, as it can be a source of serious security vulnerabilities if not handled with extreme care, potentially leading to remote code execution. The low percentage of properly escaped output (27%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website through the plugin's output.
The plugin's vulnerability history of zero recorded CVEs is positive, but it could also be an indicator of limited security scrutiny or a small user base, rather than guaranteed robust security. Coupled with the identified code quality issues, this lack of historical vulnerabilities should not be taken as a definitive sign of safety. In conclusion, while the plugin avoids common pitfalls like raw SQL and exposed entry points, the use of `create_function` and widespread unescaped output create significant security risks that need immediate attention.
Key Concerns
- Use of dangerous function create_function
- Low percentage of properly escaped output (27%)
- No nonce checks found
- No capability checks found
Posts of Current Category Security Vulnerabilities
Posts of Current Category Release Timeline
Posts of Current Category Code Analysis
Dangerous Functions Found
Output Escaping
Posts of Current Category Attack Surface
WordPress Hooks 1
Maintenance & Trust
Posts of Current Category Maintenance & Trust
Maintenance Signals
Community Trust
Posts of Current Category Alternatives
AK Featured Post Widget
akfeatured-post-widget
A widget that you can use to display your blog posts, custom post types, or woocommerce products!
WP Filter Posts – List Posts by Categories, Tags, Authors and dates
wp-filter-posts
Generate shortcode to list posts based on ids, categories, authors, tags or dates.
Latest Posts Widget
raw-latest-posts-widget
List the lastest posts from a category.
List Posts Alphabetically
list-posts-alphabetically
Lists posts alphabetically by category.
Display Category Posts Via Shortcode Lite
display-category-posts-via-shortcode-lite
Displays posts with their featured images from a specified category in a responsive grid using a simple shortcode. After installation simply go to Se …
Posts of Current Category Developer Profile
2 plugins · 50 total installs
How We Detect Posts of Current Category
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/posts-of-current-category/css/style.cssposts-of-current-category/css/style.css?ver=HTML / DOM Fingerprints
posts-of-current-category