
Root Category Recent Posts Security & Risk Analysis
wordpress.org/plugins/root-category-recent-postsAnother last posts widget which get recent posts only for the current root category.
Is Root Category Recent Posts Safe to Use in 2026?
Generally Safe
Score 85/100Root Category Recent Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "root-category-recent-posts" plugin v1.2 exhibits a generally good security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the use of prepared statements for all SQL queries and the lack of file operations or external HTTP requests are positive security indicators.
However, a significant concern arises from the low percentage (13%) of properly escaped output. This suggests a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as unsanitized data could be injected and executed within the user's browser. The lack of any nonce checks or capability checks, while potentially not an immediate issue given the limited attack surface, could become a weakness if new entry points are introduced in future versions without proper security measures.
With no recorded vulnerabilities or CVEs in its history, the plugin appears to have been developed with security in mind. However, the output escaping issue is a notable weakness that requires attention. While the plugin has a small attack surface and no history of vulnerabilities, the high potential for XSS due to insufficient output escaping represents the most significant risk.
Key Concerns
- Low percentage of properly escaped output (13%)
- No nonce checks implemented
- No capability checks implemented
Root Category Recent Posts Security Vulnerabilities
Root Category Recent Posts Code Analysis
Output Escaping
Root Category Recent Posts Attack Surface
WordPress Hooks 1
Maintenance & Trust
Root Category Recent Posts Maintenance & Trust
Maintenance Signals
Community Trust
Root Category Recent Posts Alternatives
Switch Last Posts Widget
switch-last-posts-widget
A widget which displays the latest posts according the current category.
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Social LikeBox & Feed
facebook-by-weblizar
Display your FaceBook Feed and Like box on your website with this outstanding plugin. It is completely customizable, responsive and the code is search …
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
WP Latest Posts
wp-latest-posts
Load your content from posts, page, tags or custom post type and display it anywhere in WordPress including in Gutenberg editor
Root Category Recent Posts Developer Profile
8 plugins · 310 total installs
How We Detect Root Category Recent Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
id="rcrp_widget"