
SidePost Security & Risk Analysis
wordpress.org/plugins/sidepostTo add recent posts in sidebar, with thumbnails, from specific categories...
Is SidePost Safe to Use in 2026?
Generally Safe
Score 85/100SidePost has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sidepost" v1.0.7 plugin exhibits a generally strong security posture regarding its attack surface and SQL query handling. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits external entry points for potential attackers. Furthermore, all detected SQL queries utilize prepared statements, which is a critical security best practice for preventing SQL injection vulnerabilities.
However, the analysis does reveal some areas of concern. The presence of the `create_function` dangerous function is a notable risk, as it can be exploited for code injection if not handled with extreme caution and proper sanitization, though no taint flows were detected in this version. The low percentage of properly escaped output (19%) is a significant weakness, increasing the risk of cross-site scripting (XSS) vulnerabilities. The complete lack of nonce and capability checks across all identified entry points is also a major concern, meaning that any interaction with the plugin, if it had exposed entry points, could be performed by unauthenticated or unauthorized users.
The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the lack of detected taint flows, suggests that in its current state and history, it has not been a target or source of known widespread vulnerabilities. Despite the positive aspects of its limited attack surface and SQL practices, the identified issues with output escaping and the absence of authorization checks present tangible risks that should be addressed.
Key Concerns
- Unescaped output is dangerously low
- Dangerous function create_function found
- Missing nonce checks
- Missing capability checks
SidePost Security Vulnerabilities
SidePost Release Timeline
SidePost Code Analysis
Dangerous Functions Found
Output Escaping
SidePost Attack Surface
WordPress Hooks 5
Maintenance & Trust
SidePost Maintenance & Trust
Maintenance Signals
Community Trust
SidePost Alternatives
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Recent Post Widget Thumbnail
recent-post-widget-thumbnail
Gives adaptable and highly organized recent posts. Show it through widget with thumbnails, post excerpt, post date.
Latest Posts With Thumbnails and Ads
latest-posts-with-thumbnails-and-ads
Just like the default Recent Posts widget except that posts are with thumbnails and you can show ads between them, show post date and comments count.
A5 Recent Post Widget
a5-recent-posts
With the A5 Recent Post Widget you can put your latest post in the focus and style it differently.
WP Latest Posts
wp-latest-posts
Load your content from posts, page, tags or custom post type and display it anywhere in WordPress including in Gutenberg editor
SidePost Developer Profile
3 plugins · 30 total installs
How We Detect SidePost
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sidepost/css/style.css/wp-content/plugins/sidepost/css/srpadmin.cssHTML / DOM Fingerprints
zmsprnaslovdatumokvirslikaupisatidvaupisati