
Recently Security & Risk Analysis
wordpress.org/plugins/recentlyA highly customizable, feature-packed Recent Posts widget!
Is Recently Safe to Use in 2026?
Generally Safe
Score 99/100Recently has a strong security track record. Known vulnerabilities have been patched promptly.
The 'recently' plugin v4.2.0 presents a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with only one AJAX handler, and importantly, no unprotected entry points. The taint analysis also shows no critical or high-severity flows with unsanitized paths, which is a strong indicator of secure input handling for common web vulnerabilities. However, the plugin's vulnerability history is a significant concern, with two known CVEs, including a high and a medium severity vulnerability. The common vulnerability types (XSS and unrestricted uploads) suggest a pattern of input validation and sanitization issues in past versions. While there are currently no unpatched CVEs, this history implies a recurring weakness that could resurface.
The code signals indicate areas for improvement. While a good portion of SQL queries use prepared statements (44%), the remaining 56% do not, posing a risk of SQL injection. Similarly, only 42% of outputs are properly escaped, leaving a significant portion vulnerable to Cross-Site Scripting (XSS). The presence of file operations (8) and external HTTP requests (1) also warrants careful review to ensure these are handled securely. The nonce checks and capability checks are present, which is good, but their distribution and effectiveness would require deeper code inspection.
Key Concerns
- Known CVEs exist, including high and medium severity
- Significant portion of SQL queries un-prepared
- Low percentage of properly escaped output
- Vulnerability history indicates recurring input issues
Recently Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Recently <= 3.0.4 - Authenticated (Admin+) Stored Cross-Site Scripting
Recently <= 3.0.4 - Arbitrary File Upload to Remote Code Exectution
Recently Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Recently Attack Surface
AJAX Handlers 1
WordPress Hooks 29
Maintenance & Trust
Recently Maintenance & Trust
Maintenance Signals
Community Trust
Recently Alternatives
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Social LikeBox & Feed
facebook-by-weblizar
Display your FaceBook Feed and Like box on your website with this outstanding plugin. It is completely customizable, responsive and the code is search …
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
WP Latest Posts
wp-latest-posts
Load your content from posts, page, tags or custom post type and display it anywhere in WordPress including in Gutenberg editor
WP Tab Widget
wp-tab-widget
WP Tab Widget is the AJAXified plugin which loads content by demand, and thus it makes the plugin incredibly lightweight.
Recently Developer Profile
2 plugins · 100K total installs
How We Detect Recently
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/recently/assets/admin/css/admin.css/wp-content/plugins/recently/assets/admin/js/admin.js/wp-content/plugins/recently/assets/admin/js/widget-admin.js/wp-content/plugins/recently/assets/admin/js/admin.js/wp-content/plugins/recently/assets/admin/js/widget-admin.jsrecently-admin-styles?ver=recently-admin-script?ver=recently-admin-widget-script?ver=HTML / DOM Fingerprints
recently_admin_params