
Recent Posts by Tags Security & Risk Analysis
wordpress.org/plugins/recent-posts-by-tagsThis plugin creates a widget with a list of recent posts belonging to selected tags
Is Recent Posts by Tags Safe to Use in 2026?
Generally Safe
Score 100/100Recent Posts by Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "recent-posts-by-tags" v1.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface, and crucially, all identified entry points appear to be protected. Furthermore, the complete lack of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are excellent security practices. The plugin also has no recorded vulnerability history, indicating a history of secure development or diligent patching by maintainers.
However, a significant concern arises from the low percentage of properly escaped output (17%). This suggests that user-supplied data or dynamic content might be rendered without adequate sanitization, potentially leading to Cross-Site Scripting (XSS) vulnerabilities. While taint analysis shows no critical or high-severity flows, the lack of proper output escaping is a fundamental security weakness that could be exploited in conjunction with other plugin or WordPress core functionalities. The absence of nonce and capability checks, while seemingly less impactful due to the limited attack surface, leaves a potential gap if any new entry points are introduced in the future without proper security controls.
In conclusion, the plugin benefits from a small attack surface and good practices in critical areas like SQL handling. The primary weakness lies in insufficient output escaping, which warrants attention. The historical lack of vulnerabilities is a positive sign, but the current code analysis highlights a specific area of risk that needs to be addressed to maintain a high level of security.
Key Concerns
- Low output escaping percentage
- No nonce checks
- No capability checks
Recent Posts by Tags Security Vulnerabilities
Recent Posts by Tags Code Analysis
Output Escaping
Recent Posts by Tags Attack Surface
WordPress Hooks 1
Maintenance & Trust
Recent Posts by Tags Maintenance & Trust
Maintenance Signals
Community Trust
Recent Posts by Tags Alternatives
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
Flexible Posts Widget
flexible-posts-widget
An advanced posts display widget with many options. Display posts in your sidebars any way you'd like!
Restrict Widgets
restrict-widgets
All in one widgets and sidebars management in WordPress. Allows you to hide or display widgets on specified pages and restrict access for users.
Ultimate Tag Cloud Widget
ultimate-tag-cloud-widget
This plugin aims to be the most configurable tag cloud widget out there, able to suit all your weird tag cloud needs.
Recent Posts by Tags Developer Profile
6 plugins · 2K total installs
How We Detect Recent Posts by Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
rpbt-itemrpbt-titlerpbt-dateid="recent-posts-by-tags"