Recently Updated Pages and Posts Security & Risk Analysis

wordpress.org/plugins/recently-updated-pages-and-posts

Creates a sidebar widget that lists recently updated pages and posts including newly published items.

90 active installs v1.0.2 PHP + WP 2.8+ Updated Apr 13, 2022
list-pageslist-updated-pageslist-updated-postsnewest-postsrecent-updates
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Recently Updated Pages and Posts Safe to Use in 2026?

Generally Safe

Score 85/100

Recently Updated Pages and Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "recently-updated-pages-and-posts" plugin v1.0.2 demonstrates a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) associated with this plugin, and the static analysis shows a lack of dangerous functions, file operations, external HTTP requests, and SQL injection vulnerabilities due to the use of prepared statements. The attack surface appears to be zero in terms of AJAX handlers, REST API routes, shortcodes, and cron events, suggesting a limited interaction with the WordPress core and user input.

However, significant concerns arise from the output escaping analysis. With 17 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed by the plugin that originates from user input or external sources is likely to be rendered directly in the browser without sanitization, allowing attackers to inject malicious scripts. The absence of capability checks and nonce checks, while not directly flagged as a risk due to the zero attack surface, means that if any entry points were to be introduced in future versions or through interaction with other plugins, they would lack crucial security measures.

In conclusion, while the plugin has a clean vulnerability history and avoids common pitfalls like raw SQL and dangerous functions, the severe lack of output escaping is a critical weakness that significantly undermines its security. The potential for XSS vulnerabilities is high and needs immediate attention. The absence of checks on entry points is a concern for future expandability, but the current primary risk lies with unescaped output.

Key Concerns

  • 0% properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Recently Updated Pages and Posts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Recently Updated Pages and Posts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped17 total outputs
Attack Surface

Recently Updated Pages and Posts Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initrecently_updated.php:103
Maintenance & Trust

Recently Updated Pages and Posts Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedApr 13, 2022
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs90
Developer Profile

Recently Updated Pages and Posts Developer Profile

Corey Salzano

11 plugins · 7K total installs

94
trust score
Avg Security Score
91/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Recently Updated Pages and Posts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
recently-updated-widget-listrecently-updated-widget-itemrup-excerpt
Data Attributes
id="ruwi-id="rup-excerpt
FAQ

Frequently Asked Questions about Recently Updated Pages and Posts