
Recent Posts From Each Category Security & Risk Analysis
wordpress.org/plugins/recent-posts-from-each-categoryDisplay Recent Posts From Each/Selected Category. Category Box View Plugin.
Is Recent Posts From Each Category Safe to Use in 2026?
Use With Caution
Score 63/100Recent Posts From Each Category has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "recent-posts-from-each-category" plugin exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and has no dangerous function calls or file operations, significant concerns exist regarding its input validation and authentication mechanisms. The static analysis highlights a concerning lack of nonce checks and capability checks, particularly on its AJAX handler, which is exposed without authentication. This creates a significant attack vector. The plugin also struggles with output escaping, with only 1% of outputs being properly handled, increasing the risk of cross-site scripting (XSS) vulnerabilities if attacker-controlled data is ever displayed.
The vulnerability history, unfortunately, points to a recurring pattern. The presence of one unpatched medium severity CVE, previously identified as Cross-Site Request Forgery (CSRF), combined with the lack of robust authentication on its AJAX endpoint, suggests that similar vulnerabilities could be exploited. The fact that a previous CSRF vulnerability exists and there are no nonce checks on the AJAX handler is a strong indicator that this plugin is susceptible to these types of attacks. Overall, while the plugin has some solid foundations in data handling, the critical gaps in authentication and output sanitization, coupled with its vulnerability history, present a notable risk that requires immediate attention.
Key Concerns
- Unprotected AJAX handler
- 100% unescaped output observed
- Unpatched medium severity CVE
- Missing nonce checks
- Missing capability checks
Recent Posts From Each Category Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Recent Posts From Each Category <= 1.4 - Cross-Site Request Forgery
Recent Posts From Each Category Release Timeline
Recent Posts From Each Category Code Analysis
SQL Query Safety
Output Escaping
Recent Posts From Each Category Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Recent Posts From Each Category Maintenance & Trust
Maintenance Signals
Community Trust
Recent Posts From Each Category Alternatives
AJ Category Posts
aj-category-posts
A simple & powerful plugin to display WordPress posts by category using customizable shortcodes. Ideal for bloggers, news websites & content creators.
Category Posts Widget
category-posts
Adds a widget that shows the most recent posts from a single category.
Latest Posts
latest-posts
Latest posts widget to display recent posts from category.
Recent Posts by Category Widget
recent-posts-by-category-widget
Just like the default Recent Posts widget except you can choose a category to pull posts from.
Custom Recent Posts Widget
custom-recent-posts-widget
A widget to show recent posts list based on categories or tags
Recent Posts From Each Category Developer Profile
8 plugins · 440 total installs
How We Detect Recent Posts From Each Category
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/recent-posts-from-each-category/assets/css/sunrise.css/wp-content/plugins/recent-posts-from-each-category/assets/js/form.js/wp-content/plugins/recent-posts-from-each-category/assets/js/sunrise.js/wp-content/plugins/recent-posts-from-each-category/assets/js/form.js/wp-content/plugins/recent-posts-from-each-category/assets/js/sunrise.jsrecent-posts-from-each-category/assets/css/sunrise.css?ver=recent-posts-from-each-category/assets/js/form.js?ver=recent-posts-from-each-category/assets/js/sunrise.js?ver=HTML / DOM Fingerprints
rpfc-widgetdata-rpfc-widgetRpfec_Sunrise_Plugin_Framework[recent_posts_from_each_category]