Related Posts Thumbnails Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/related-posts-thumbnailsRelated Posts by WPBrigade is The Best Customizable plugin, that nicely displays related posts thumbnails under the post.
Is Related Posts Thumbnails Plugin for WordPress Safe to Use in 2026?
Mostly Safe
Score 78/100Related Posts Thumbnails Plugin for WordPress is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "related-posts-thumbnails" v4.3.2 plugin exhibits a mixed security posture. On the positive side, there are no critical or high-severity taint flows identified, and the majority of SQL queries utilize prepared statements. The presence of numerous nonce and capability checks, as well as a limited attack surface, are also commendable. However, a significant concern is the presence of an unpatched medium-severity vulnerability, indicated by the vulnerability history. This suggests a potential for known exploits targeting this plugin. Furthermore, the static analysis reveals that only 42% of output is properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if malicious data is processed. The taint analysis also flagged one flow with unsanitized paths, which, while not critical, warrants further investigation to understand its potential impact.
While the plugin demonstrates some good security practices, the unpatched vulnerability and the high percentage of unescaped output represent notable weaknesses. The vulnerability history, showing only CSRF in the past, might be misleading given the current static analysis findings. The overall risk is elevated due to the known unpatched vulnerability, which could be exploited by attackers. The unescaped output, combined with the unsanitized path flow, creates a risk of XSS or path traversal, though the severity of these specific instances is not explicitly defined as critical or high in the provided data.
Key Concerns
- 1 unpatched medium vulnerability
- 42% of output properly escaped
- 1 flow with unsanitized paths
Related Posts Thumbnails Plugin for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Related Posts Thumbnails Plugin for WordPress <= 4.3.1 - Cross-Site Request Forgery
Related Posts Thumbnails Plugin for WordPress Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Related Posts Thumbnails Plugin for WordPress Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
Related Posts Thumbnails Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Related Posts Thumbnails Plugin for WordPress Alternatives
Related Posts With Slider
related-posts-with-slider
This plugin brings Related post slider to the WordPress blog post.
Visualmodo Related Posts
visualmodo-related-posts
Visualmodo Related Posts for WordPress will help increase your visitors’ time on website and decrease your bounce rate.
Floating Related Posts by Views or Publish Date
floating-related-posts-by-views-or-publish-date
Increase your page views and bounce rate with Floating Related Posts by Views or Publish Date
Inline Related Posts
intelly-related-posts
Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Related Posts Thumbnails Plugin for WordPress Developer Profile
1 plugin · 20K total installs
How We Detect Related Posts Thumbnails Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/related-posts-thumbnails/style.css/wp-content/plugins/related-posts-thumbnails/admin.css/wp-content/plugins/related-posts-thumbnails/js/related-posts-thumbnails-public.js/wp-content/plugins/related-posts-thumbnails/js/related-posts-thumbnails-admin.js/wp-content/plugins/related-posts-thumbnails/js/amp.js/wp-content/plugins/related-posts-thumbnails/css/slick.cssrelated-posts-thumbnails/js/related-posts-thumbnails-public.jsrelated-posts-thumbnails/js/related-posts-thumbnails-admin.jsrelated-posts-thumbnails/js/amp.jsrelated-posts-thumbnails/css/slick.cssrelated-posts-thumbnails/style.css?ver=related-posts-thumbnails/admin.css?ver=related-posts-thumbnails/js/related-posts-thumbnails-public.js?ver=related-posts-thumbnails/js/related-posts-thumbnails-admin.js?ver=related-posts-thumbnails/js/amp.js?ver=related-posts-thumbnails/css/slick.css?ver=HTML / DOM Fingerprints
related-posts-thumbnailsrpt-related-posts-thumbnailsrpt-column-wrapperrpt-title<!-- Related Posts Thumbnails -->data-post-iddata-post-typedata-post-titlerelated_posts_thumbnails_data[related-posts-thumbnails]