Root Category Recent Posts Security & Risk Analysis

wordpress.org/plugins/root-category-recent-posts

Another last posts widget which get recent posts only for the current root category.

10 active installs v1.2 PHP + WP 3.6.1+ Updated Dec 9, 2013
last-postsrecent-postsroot-categorywidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Root Category Recent Posts Safe to Use in 2026?

Generally Safe

Score 85/100

Root Category Recent Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "root-category-recent-posts" plugin v1.2 exhibits a generally good security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the use of prepared statements for all SQL queries and the lack of file operations or external HTTP requests are positive security indicators.

However, a significant concern arises from the low percentage (13%) of properly escaped output. This suggests a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as unsanitized data could be injected and executed within the user's browser. The lack of any nonce checks or capability checks, while potentially not an immediate issue given the limited attack surface, could become a weakness if new entry points are introduced in future versions without proper security measures.

With no recorded vulnerabilities or CVEs in its history, the plugin appears to have been developed with security in mind. However, the output escaping issue is a notable weakness that requires attention. While the plugin has a small attack surface and no history of vulnerabilities, the high potential for XSS due to insufficient output escaping represents the most significant risk.

Key Concerns

  • Low percentage of properly escaped output (13%)
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Root Category Recent Posts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Root Category Recent Posts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

13% escaped24 total outputs
Attack Surface

Root Category Recent Posts Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initroot-category-recent-posts.php:20
Maintenance & Trust

Root Category Recent Posts Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedDec 9, 2013
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Root Category Recent Posts Developer Profile

LordPretender

8 plugins · 310 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Root Category Recent Posts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
id="rcrp_widget"
FAQ

Frequently Asked Questions about Root Category Recent Posts