
Related Posts By PickPlugins Security & Risk Analysis
wordpress.org/plugins/related-postDisplay Related Post under post by taxonomy and terms.
Is Related Posts By PickPlugins Safe to Use in 2026?
Generally Safe
Score 98/100Related Posts By PickPlugins has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "related-post" plugin v2.0.66 exhibits a generally good security posture based on the static analysis, with a very high percentage of properly escaped outputs and no critical or high-severity vulnerabilities detected in taint analysis. The plugin also demonstrates an awareness of security best practices by implementing nonce and capability checks on its entry points. The limited attack surface, with no unprotected entry points, is a positive indicator.
However, the plugin's vulnerability history presents a significant concern. With three known medium-severity CVEs, including Cross-Site Request Forgery, Improper Access Control, and Cross-Site Scripting, it suggests a recurring pattern of vulnerabilities. The fact that these vulnerabilities were historically present, even if currently patched, indicates potential weaknesses in the development process that could resurface in future versions. While the current version shows no unpatched vulnerabilities, this history warrants careful monitoring and a cautious approach to deployment.
In conclusion, the "related-post" plugin v2.0.66 has strengths in its current code quality and implementation of basic security checks. Nevertheless, the past vulnerability record is a substantial weakness that should not be overlooked. Organizations should weigh the benefits of the plugin against the historical risk and consider the plugin vendor's responsiveness to security issues.
Key Concerns
- Multiple medium severity CVEs historically
- 50% of SQL queries not using prepared statements
Related Posts By PickPlugins Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.59 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.58 - Sensitive Information Exposure
Related Post <= 2.0.53 - Authenticated (Contributor+) Stored Cross-Site Scripting
Related Posts By PickPlugins Release Timeline
Related Posts By PickPlugins Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Related Posts By PickPlugins Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 39
Maintenance & Trust
Related Posts By PickPlugins Maintenance & Trust
Maintenance Signals
Community Trust
Related Posts By PickPlugins Alternatives
Inline Related Posts
intelly-related-posts
Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
Related Posts for WordPress
related-posts-for-wp
The best WordPress plugin for related posts. Simple, flexible, powerful algorithm, and built-in caching. Fully setup with only 1 click!
Internal Linking of Related Contents
internal-linking-of-related-contents
Internal Linking of Related Contents allows you to automatically insert inline related posts within your WordPress articles.
Super Related Posts – Lightweight, High Performance Algorithm & Increase Traffic!
super-related-posts
Related Posts Plugin to improve Traffic & Bounce-Rate with Superior Algorithm. ZERO Server Load & Highly Configurable Related Post Plugin.
Mevabi – Related Posts Inline
mevabi-related-posts-inline
Display related posts inline within your content or at the end, with three modern designs and full color customization.
Related Posts By PickPlugins Developer Profile
14 plugins · 94K total installs
How We Detect Related Posts By PickPlugins
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/related-post/assets/front/css/related-post.css/wp-content/plugins/related-post/assets/front/css/font-awesome-5.css/wp-content/plugins/related-post/assets/front/css/font-awesome-4.css/wp-content/plugins/related-post/assets/front/js/owl.carousel.min.js/wp-content/plugins/related-post/assets/front/css/owl.carousel.min.css/wp-content/plugins/related-post/assets/admin/js/scripts.js/wp-content/plugins/related-post/assets/settings-tabs/settings-tabs.js/wp-content/plugins/related-post/assets/settings-tabs/settings-tabs.cssrelated-post/assets/front/css/related-post.cssrelated-post/assets/front/css/font-awesome-5.cssrelated-post/assets/front/css/font-awesome-4.cssrelated-post/assets/front/js/owl.carousel.min.jsrelated-post/assets/front/css/owl.carousel.min.cssrelated-post/assets/admin/js/scripts.js+2 moreHTML / DOM Fingerprints
<!-- Related Post -->data-related-post-iddata-related-post-auto-playdata-related-post-auto-play-timedata-related-post-navdata-related-post-dotsdata-related-post-margin+5 morerelated_post_ajax[related_post][related_post_category][related_post_tag][related_post_author]