Recent Post Scroll Widget Security & Risk Analysis

wordpress.org/plugins/qsd-owl-slider

Recent Post Scroll Widget is very customizable post widget . There are a lot's of option to display your recent post

20 active installs v1.8 PHP + WP 3.0.1+ Updated Jan 17, 2021
latest-postpost-listpost-widgetrecent-postrecent-post-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Recent Post Scroll Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Recent Post Scroll Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the qsd-owl-slider v1.8 plugin exhibits a generally positive security posture. The absence of any recorded vulnerabilities (CVEs) and the lack of critical or high severity findings in taint analysis are strong indicators of responsible development practices. Furthermore, the plugin appears to have a minimal attack surface, with no reported AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, no unprotected entry points were identified.

However, the static analysis does reveal a significant concern regarding output escaping. With only 32% of outputs properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is not properly sanitized before being displayed could be exploited by attackers. The lack of any recorded vulnerability history, while generally good, could also be interpreted as a lack of thorough security auditing or public disclosure over time. Nevertheless, the robust use of prepared statements for all SQL queries is a commendable practice that mitigates SQL injection risks.

In conclusion, while the plugin demonstrates strengths in its limited attack surface and secure database interaction, the prevalent issue with output escaping presents a notable risk that requires immediate attention. Addressing the unescaped outputs is crucial to ensure a more secure user experience and protect against potential client-side attacks.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Recent Post Scroll Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Recent Post Scroll Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
77
36 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

32% escaped113 total outputs
Attack Surface

Recent Post Scroll Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwp_footerincludes\Rpc_class.php:393
actionwp_enqueue_scriptsincludes\rpc_script.php:10
actionadmin_enqueue_scriptsincludes\rpc_script.php:17
actionplugins_loadedrecent-post.php:38
actionwidgets_initrecent-post.php:51
Maintenance & Trust

Recent Post Scroll Widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedJan 17, 2021
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Recent Post Scroll Widget Developer Profile

quazisazzad

5 plugins · 450 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Recent Post Scroll Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/qsd-owl-slider/css/bootstrap.min.css/wp-content/plugins/qsd-owl-slider/css/style.css/wp-content/plugins/qsd-owl-slider/scripts/newsboxscript.js/wp-content/plugins/qsd-owl-slider/scripts/jquery.bootstrap.newsbox.min.js/wp-content/plugins/qsd-owl-slider/scripts/color-picker.js
Script Paths
css/bootstrap.min.csscss/style.cssscripts/newsboxscript.jsscripts/jquery.bootstrap.newsbox.min.jsscripts/color-picker.js

HTML / DOM Fingerprints

CSS Classes
panel-heading
Data Attributes
data-slidedata-targetdata-parentdata-keyboarddata-wrapdata-interval+45 more
JS Globals
jQuery$
Shortcode Output
[recent_post_scroll][recent_post_scroll title=[recent_post_scroll title_icon=[recent_post_scroll ppr=
FAQ

Frequently Asked Questions about Recent Post Scroll Widget