
Automated Related Posts by Tags | inventivo Security & Risk Analysis
wordpress.org/plugins/related-posts-by-tags-inventivoAutomated Related Posts by Tags Plugin for WordPress
Is Automated Related Posts by Tags | inventivo Safe to Use in 2026?
Generally Safe
Score 85/100Automated Related Posts by Tags | inventivo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'related-posts-by-tags-inventivo' v1.0.2 exhibits a generally positive security posture based on the provided static analysis. It demonstrates strong practices by avoiding dangerous functions, using prepared statements exclusively for its SQL queries, and not making external HTTP requests. The lack of any recorded vulnerabilities in its history is also a very encouraging sign. However, there are significant concerns regarding output escaping, as 100% of outputs are not properly escaped. This opens the door to potential Cross-Site Scripting (XSS) vulnerabilities, especially given the presence of a shortcode which often involves user-generated content being displayed on the frontend. The absence of nonce checks and capability checks, coupled with the lack of auth checks on its single entry point (the shortcode), further amplifies the risk associated with unescaped output. While taint analysis did not reveal any immediate issues, the unescaped outputs are a critical oversight that needs immediate attention to prevent potential XSS attacks. The plugin's strengths lie in its clean code regarding SQL and external requests, but its weakness in output sanitization is a serious vulnerability that overshadows these strengths.
Key Concerns
- Unescaped output (100%)
- Missing nonce checks
- Missing capability checks
- Shortcode without auth check
Automated Related Posts by Tags | inventivo Security Vulnerabilities
Automated Related Posts by Tags | inventivo Code Analysis
SQL Query Safety
Output Escaping
Automated Related Posts by Tags | inventivo Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Automated Related Posts by Tags | inventivo Maintenance & Trust
Maintenance Signals
Community Trust
Automated Related Posts by Tags | inventivo Alternatives
Inline Related Posts
intelly-related-posts
Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
YARPP – Yet Another Related Posts Plugin
yet-another-related-posts-plugin
The best WordPress plugin for displaying related posts. Simple and flexible, with a powerful proven algorithm and inbuilt caching.
Contextual Related Posts
contextual-related-posts
Keep visitors on your site longer with intelligent, fast-loading, contextually related posts. Block, shortcode, custom post type and widget ready.
Related Posts for WordPress
related-posts-for-wp
The best WordPress plugin for related posts. Simple, flexible, powerful algorithm, and built-in caching. Fully setup with only 1 click!
Automated Related Posts by Tags | inventivo Developer Profile
5 plugins · 260 total installs
How We Detect Automated Related Posts by Tags | inventivo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/related-posts-by-tags-inventivo/public/css/relatedpostsbytags.css/wp-content/plugins/related-posts-by-tags-inventivo/public/js/jquery.matchHeight.js/wp-content/plugins/related-posts-by-tags-inventivo/public/js/relatedpostsbytags.js/wp-content/plugins/related-posts-by-tags-inventivo/public/js/jquery.matchHeight.js/wp-content/plugins/related-posts-by-tags-inventivo/public/js/relatedpostsbytags.jsrelated-posts-by-tags-inventivo/public/css/relatedpostsbytags.css?ver=related-posts-by-tags-inventivo/public/js/jquery.matchHeight.js?ver=related-posts-by-tags-inventivo/public/js/relatedpostsbytags.js?ver=HTML / DOM Fingerprints
hreflang-x-default-tag-for-wpml-inventivo-wrapperhreflang-x-default-tag-for-wpml-inventivo-elementrelated-postCSS nur laden, wenn shortcode vorhanden istdata-plugin-slug="related-posts-by-tags-inventivo"inventivoRelatedPosts<div id="related-posts"<span class="h1">Related posts</span>