
SM Recent Post Security & Risk Analysis
wordpress.org/plugins/sm-recent-postsSM Recent Post is a wordpress widget plugin to display Recent Posts in site sidebar.
Is SM Recent Post Safe to Use in 2026?
Generally Safe
Score 85/100SM Recent Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'sm-recent-posts' v1.0.0 plugin exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of known CVEs, dangerous functions, SQL injection risks through prepared statements, file operations, and external HTTP requests are strong indicators of good development practices. The plugin also doesn't appear to have a large attack surface, with no reported AJAX handlers, REST API routes, shortcodes, or cron events being exposed without proper authentication or permission checks. This suggests the plugin is likely focused on a limited functionality that doesn't introduce many direct entry points for attackers.
However, a significant concern arises from the low percentage of properly escaped output (18%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data or dynamically generated content is not adequately sanitized before being displayed. While no taint flows were detected in this specific analysis, the lack of robust output escaping is a prevalent pathway for XSS attacks and represents a considerable weakness. The absence of nonce checks and capability checks, while not explicitly flagged as issues in the static analysis (likely due to a lack of exploitable entry points detected), could become a concern if the plugin's functionality were to expand or if entry points were introduced in the future without these security measures.
In conclusion, the 'sm-recent-posts' plugin has strengths in its limited attack surface and secure handling of database queries and external communications. Its vulnerability history is clean, which is a positive sign. Nevertheless, the poor output escaping is a critical area of concern that significantly lowers its overall security score. It is crucial to address the output escaping issue to mitigate the risk of XSS vulnerabilities.
Key Concerns
- Low percentage of properly escaped output
SM Recent Post Security Vulnerabilities
SM Recent Post Code Analysis
Output Escaping
SM Recent Post Attack Surface
WordPress Hooks 1
Maintenance & Trust
SM Recent Post Maintenance & Trust
Maintenance Signals
Community Trust
SM Recent Post Alternatives
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Social LikeBox & Feed
facebook-by-weblizar
Display your FaceBook Feed and Like box on your website with this outstanding plugin. It is completely customizable, responsive and the code is search …
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
WP Latest Posts
wp-latest-posts
Load your content from posts, page, tags or custom post type and display it anywhere in WordPress including in Gutenberg editor
WP Tab Widget
wp-tab-widget
WP Tab Widget is the AJAXified plugin which loads content by demand, and thus it makes the plugin incredibly lightweight.
SM Recent Post Developer Profile
10 plugins · 650 total installs
How We Detect SM Recent Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sm-recent-posts/assets/img/no-thumbnail.pngHTML / DOM Fingerprints
SMRecentPost_Widgetid='sm_recent_post'SM_RECENT_POSTS_URL