
Related Posts by Taxonomy Security & Risk Analysis
wordpress.org/plugins/related-posts-by-taxonomyDisplay a list of related posts on your site based on the most terms in common. Supports thumbnails, shortcodes, a widget and more.
Is Related Posts by Taxonomy Safe to Use in 2026?
Generally Safe
Score 99/100Related Posts by Taxonomy has a strong security track record. Known vulnerabilities have been patched promptly.
The 'related-posts-by-taxonomy' plugin v2.7.8 exhibits a generally good security posture with several strengths, including no identified critical or high severity taint flows, no external HTTP requests, and no file operations. The plugin also has a limited attack surface with all identified entry points featuring authentication checks. However, there are areas for improvement. The static analysis indicates that 33% of SQL queries are not using prepared statements, which can be a potential vector for SQL injection if the inputs are not meticulously sanitized, though no specific taint flows were found in this analysis.
The plugin's vulnerability history shows one known medium severity CVE related to Cross-Site Scripting (XSS). While this vulnerability is currently unpatched according to the data, the last vulnerability was dated in the future (2026-01-15), which might be an anomaly in the provided data. The fact that the only known vulnerability was medium severity and involved XSS suggests that input validation and output escaping might be areas where the plugin could be more robust, as evidenced by only 69% of outputs being properly escaped.
In conclusion, the plugin demonstrates a commitment to security by minimizing its attack surface and implementing some security checks. The lack of critical vulnerabilities or taint flows is a positive sign. However, the presence of non-prepared SQL queries and the historical XSS vulnerability, coupled with a moderate percentage of unescaped output, highlight potential weaknesses that require attention for a more secure implementation.
Key Concerns
- Unpatched CVE (Medium Severity)
- SQL queries not using prepared statements (33%)
- Output escaping not fully implemented (69%)
Related Posts by Taxonomy Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Related Posts by Taxonomy <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'related_posts_by_tax' Shortcode
Related Posts by Taxonomy Code Analysis
SQL Query Safety
Output Escaping
Related Posts by Taxonomy Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 37
Maintenance & Trust
Related Posts by Taxonomy Maintenance & Trust
Maintenance Signals
Community Trust
Related Posts by Taxonomy Alternatives
Related Posts Thumbnails Plugin for WordPress
related-posts-thumbnails
Related Posts by WPBrigade is The Best Customizable plugin, that nicely displays related posts thumbnails under the post.
Wp-Thumbie – Related Posts with thumbnails for WordPress
wp-thumbie
Show user defined number of related / similar posts with thumbnail image
Simply Related Posts
simply-related-posts
A widget that simply gives you related posts by taxonomy. Four settings to customize the widget: title, taxonomy, related posts count, excludet terms
Recent Related Post And Page
recent-related-post-and-page
Show Recent Related Posts Pages Using Widget & Shortcode
Related Posts With Slider
related-posts-with-slider
This plugin brings Related post slider to the WordPress blog post.
Related Posts by Taxonomy Developer Profile
6 plugins · 11K total installs
How We Detect Related Posts by Taxonomy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/related-posts-by-taxonomy/includes/assets/js/lazy-loading.min.js/wp-content/plugins/related-posts-by-taxonomy/includes/assets/js/lazy-loading.js/wp-content/plugins/related-posts-by-taxonomy/includes/assets/css/styles.css/wp-content/plugins/related-posts-by-taxonomy/includes/assets/js/lazy-loading.min.js/wp-content/plugins/related-posts-by-taxonomy/includes/assets/js/lazy-loading.jsrelated-posts-by-taxonomy/includes/assets/css/styles.css?ver=rpbt-lazy-loadingHTML / DOM Fingerprints
rpbt-related-postsdata-post-iddata-typedata-taxonomydata-termsdata-orderdata-orderby+7 morerpbt_lazy_loading/wp-json/rpbt/v1/posts[related_posts_by_taxonomy]