
Pro Related Post Widget Security & Risk Analysis
wordpress.org/plugins/pro-related-post-widgetPro Related Post Widget plugin.dynamically show related post according to post.
Is Pro Related Post Widget Safe to Use in 2026?
Generally Safe
Score 85/100Pro Related Post Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'pro-related-post-widget' plugin v1.0 presents a mixed security posture. On the positive side, it boasts zero known CVEs, no external HTTP requests, and no file operations, all of which contribute to a reduced attack surface. Furthermore, all SQL queries are properly prepared, which is a significant strength. However, the code analysis reveals critical areas for improvement. The presence of the dangerous `create_function` construct is a notable concern, as it can be exploited for code injection if user input is not meticulously sanitized before being passed to it. The low percentage of properly escaped output (26%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. The absence of nonce checks and capability checks on any entry points, coupled with the complete lack of an apparent attack surface (which might suggest it's not actively used or exposed), means that if any entry points were to be introduced or discovered, they would likely be unprotected. Overall, while the plugin has a clean vulnerability history, the static analysis highlights significant weaknesses in output sanitization and the use of a deprecated, insecure function that could lead to serious security breaches if exploited.
Key Concerns
- Use of dangerous function: create_function
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
Pro Related Post Widget Security Vulnerabilities
Pro Related Post Widget Code Analysis
Dangerous Functions Found
Output Escaping
Pro Related Post Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Pro Related Post Widget Maintenance & Trust
Maintenance Signals
Community Trust
Pro Related Post Widget Alternatives
Related Posts Widget
related-posts-widget
Adds a widget that shows posts related to the current post based on tags.
WP Related Post With Pagination
wp-related-post-with-pagination
Allows you add latest post widget in your sidebar with ajax pagination & customizable template.
Social LikeBox & Feed
facebook-by-weblizar
Display your FaceBook Feed and Like box on your website with this outstanding plugin. It is completely customizable, responsive and the code is search …
Custom Related Posts
custom-related-posts
Manual related posts without slowing down your website!
Gabfire Widget Pack
gabfire-widget-pack
The Gabfire Widget Pack contains over a dozen useful widgets to extend your WordPress site. It is a free plugin that will work with ANY theme.
Pro Related Post Widget Developer Profile
7 plugins · 3K total installs
How We Detect Pro Related Post Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
pro_related_postPro Related Posts