
Recently Updated Pages Security & Risk Analysis
wordpress.org/plugins/recently-updated-pagesThis plugin shows recently updated pages on the sidebar widget.
Is Recently Updated Pages Safe to Use in 2026?
Generally Safe
Score 92/100Recently Updated Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'recently-updated-pages' plugin version 2.0.0 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by not utilizing dangerous functions, avoiding file operations, and making no external HTTP requests. All SQL queries are properly prepared, and there are no known historical vulnerabilities or CVEs associated with this plugin, indicating a potentially stable codebase. However, significant concerns arise from the lack of output escaping and the absence of critical security checks.
The static analysis reveals that 100% of outputs are not properly escaped. This is a major security risk, as any data displayed by the plugin could be vulnerable to Cross-Site Scripting (XSS) attacks if user-controlled input is not sanitized before being rendered. Additionally, the plugin lacks nonce checks and capability checks for its entry points, including the sole shortcode. While the attack surface is small and there are no unprotected AJAX handlers or REST API routes, the shortcode's lack of validation opens it up to potential abuse where malicious content could be injected and executed.
Given the absence of historical vulnerabilities, it's possible these weaknesses have not been exploited yet, or the plugin's functionality is limited in scope, thus reducing its attractiveness to attackers. Nevertheless, the unescaped output and missing capability checks on the shortcode represent actionable security flaws that should be addressed to improve the plugin's overall security.
Key Concerns
- Outputs are not properly escaped (100%)
- Missing capability checks on entry points
- Missing nonce checks on entry points
Recently Updated Pages Security Vulnerabilities
Recently Updated Pages Code Analysis
SQL Query Safety
Output Escaping
Recently Updated Pages Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Recently Updated Pages Maintenance & Trust
Maintenance Signals
Community Trust
Recently Updated Pages Alternatives
Recently Updated Pages and Posts
recently-updated-pages-and-posts
Creates a sidebar widget that lists recently updated pages and posts including newly published items.
VK Link Target Controller
vk-link-target-controller
Redirect your visitors to another page than the post content when they click on the post title.
Last Modified Timestamp
last-modified-timestamp
Adds the last modified time to the admin interface as well as a [last-modified] shortcode to use on the front-end.
Recent Changes
recent-changes
A widget and short code to show the most recently modified pages, posts or both allowing visitors to review recent changes as they would on a wiki.
Categories Recent Posts Widget
category-recent-posts-widget
This widget displays the recent posts on a category page for that category
Recently Updated Pages Developer Profile
2 plugins · 310 total installs
How We Detect Recently Updated Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/recently-updated-pages/style.css/wp-content/plugins/recently-updated-pages/js/recently-updated-pages.js/wp-content/plugins/recently-updated-pages/js/recently-updated-pages.jsrecently-updated-pages/style.css?ver=recently-updated-pages/js/recently-updated-pages.js?ver=HTML / DOM Fingerprints
page_itempage-item-widgettitlewidget-wrapid="recently_updated_pages"name="recently_updated_pages"id="recently_updated_pages_title"name="recently_updated_pages_title"id="recently_updated_pages_totalPagesToShow"name="recently_updated_pages_totalPagesToShow"+6 more