Quick Recommend Security & Risk Analysis

wordpress.org/plugins/quick-recommend

Add a recommendation box to the bottom of your posts. Great for promoting books, movies, music and other products when that is not the primary focus o …

0 active installs v1.2 PHP 5.2.4+ WP 4.9+ Updated Feb 23, 2018
booksmoviesrecommendationrecommendations
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Quick Recommend Safe to Use in 2026?

Generally Safe

Score 85/100

Quick Recommend has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'quick-recommend' v1.2 plugin exhibits a strong security posture in several key areas. Notably, it has no recorded vulnerabilities (CVEs) and its static analysis shows no dangerous functions, file operations, or external HTTP requests. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant strength, minimizing the plugin's attack surface. Furthermore, all SQL queries utilize prepared statements, which is excellent practice for preventing SQL injection vulnerabilities. However, a critical weakness lies in its output escaping. With 100% of analyzed outputs being unescaped, the plugin is highly susceptible to Cross-Site Scripting (XSS) attacks. The lack of nonce and capability checks, while mitigated by the lack of public entry points, still represents a potential blind spot if any future entry points are added without proper authorization checks. The bundled TinyMCE library, if outdated, could also present a risk, though this specific analysis doesn't provide version information for it. Overall, while the plugin excels at preventing common web vulnerabilities like SQL injection and has a minimal attack surface, the lack of output escaping poses a severe risk of XSS.

Key Concerns

  • All output escaping is missing
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Quick Recommend Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Quick Recommend Release Timeline

v1.1
Code Analysis
Analyzed Mar 17, 2026

Quick Recommend Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

SQL Query Safety

100% prepared4 total queries

Output Escaping

0% escaped3 total outputs
Attack Surface

Quick Recommend Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actioninitcpt\recommendations.php:45
actioninitcpt\recommendations.php:96
filtermanage_edit-recommendation_columnsquick-recommend.php:87
filtermanage_recommendation_posts_custom_columnquick-recommend.php:91
actionadmin_head-edit.phpquick-recommend.php:92
actionwp_enqueue_scriptsquick-recommend.php:96
actionadmin_menuquick-recommend.php:99
actionadmin_enqueue_scriptsquick-recommend.php:102
actionadmin_initquick-recommend.php:105
actionadmin_noticesquick-recommend.php:108
filterthe_contentquick-recommend.php:112
filteracf/fields/relationship/result/name=qrec_recommendationquick-recommend.php:115
filterthe_titlequick-recommend.php:164
filteracf/settings/pathquick-recommend.php:308
filteracf/settings/dirquick-recommend.php:316
filteracf/settings/show_adminquick-recommend.php:329
Maintenance & Trust

Quick Recommend Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedFeb 23, 2018
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Quick Recommend Developer Profile

shedsimas

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Quick Recommend

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quick-recommend/quick-recommend.js/wp-content/plugins/quick-recommend/quick-recommend.css
Version Parameters
quick-recommend/quick-recommend.css?ver=quick-recommend/quick-recommend.js?ver=

HTML / DOM Fingerprints

CSS Classes
quick-recommend-box
Data Attributes
data-field_name="qrec_recommendation"data-post_id=""
FAQ

Frequently Asked Questions about Quick Recommend