
Quick Recommend Security & Risk Analysis
wordpress.org/plugins/quick-recommendAdd a recommendation box to the bottom of your posts. Great for promoting books, movies, music and other products when that is not the primary focus o …
Is Quick Recommend Safe to Use in 2026?
Generally Safe
Score 85/100Quick Recommend has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'quick-recommend' v1.2 plugin exhibits a strong security posture in several key areas. Notably, it has no recorded vulnerabilities (CVEs) and its static analysis shows no dangerous functions, file operations, or external HTTP requests. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant strength, minimizing the plugin's attack surface. Furthermore, all SQL queries utilize prepared statements, which is excellent practice for preventing SQL injection vulnerabilities. However, a critical weakness lies in its output escaping. With 100% of analyzed outputs being unescaped, the plugin is highly susceptible to Cross-Site Scripting (XSS) attacks. The lack of nonce and capability checks, while mitigated by the lack of public entry points, still represents a potential blind spot if any future entry points are added without proper authorization checks. The bundled TinyMCE library, if outdated, could also present a risk, though this specific analysis doesn't provide version information for it. Overall, while the plugin excels at preventing common web vulnerabilities like SQL injection and has a minimal attack surface, the lack of output escaping poses a severe risk of XSS.
Key Concerns
- All output escaping is missing
- No nonce checks
- No capability checks
Quick Recommend Security Vulnerabilities
Quick Recommend Release Timeline
Quick Recommend Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Quick Recommend Attack Surface
WordPress Hooks 16
Maintenance & Trust
Quick Recommend Maintenance & Trust
Maintenance Signals
Community Trust
Quick Recommend Alternatives
Recommendations TasteDive
recommendations-tastedive
Automatically recommend similar music, movies, TV shows, books and games with TasteDive.
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Related Products – Create Upsells, Cross-sells, and Product Recommendations for WooCommerce
wt-woocommerce-related-products
This WooCommerce related products plugin, lets you create upsells, and cross-sells with smart WooCommerce product recommendations widget.
Widgets for Reviews & Recommendations
free-facebook-reviews-and-recommendations-widgets
Embed Facebook reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Facebook recommendations.
Taboola
taboola
Use the Taboola plugin to generate revenue from native ads and drive engagement with editorial content.
Quick Recommend Developer Profile
1 plugin · 0 total installs
How We Detect Quick Recommend
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/quick-recommend/quick-recommend.js/wp-content/plugins/quick-recommend/quick-recommend.cssquick-recommend/quick-recommend.css?ver=quick-recommend/quick-recommend.js?ver=HTML / DOM Fingerprints
quick-recommend-boxdata-field_name="qrec_recommendation"data-post_id=""