EZ Related Posts Footer Links and Widget Security & Risk Analysis

wordpress.org/plugins/spostarbust

Display a linked list of related Posts by Tags or Categories at the bottom of every post or on the sidebar. Options to show Post Date and Excerpts.

200 active installs v1.2.04.25 PHP + WP 2.6+ Updated Apr 28, 2025
categorieslistpostsrelatedtags
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 7, 2025
Safety Verdict

Is EZ Related Posts Footer Links and Widget Safe to Use in 2026?

Generally Safe

Score 99/100

EZ Related Posts Footer Links and Widget has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 7, 2025Updated 11mo ago
Risk Assessment

The "spostarbust" v1.2.04.25 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no apparent attack surface through common entry points like AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding file operations or external HTTP requests. The presence of nonce checks is also encouraging.

However, there are notable areas of concern. A significant portion of output (47%) is not properly escaped, indicating a potential risk of Cross-Site Scripting (XSS) vulnerabilities if untrusted data is rendered directly. The absence of capability checks on any entry points, though the attack surface is currently zero, means that if entry points are added in the future, they may be unprotected by WordPress's role-based access control. The vulnerability history, while currently showing no unpatched vulnerabilities, does list one previous CVE related to Cross-Site Request Forgery (CSRF), suggesting a past tendency towards this type of flaw.

In conclusion, while the plugin has made strides in secure coding practices, the unescaped output represents a tangible risk that needs addressing. The history of CSRF vulnerabilities, even if resolved, warrants continued vigilance. Future development should prioritize implementing capability checks on any new entry points and ensuring all output is thoroughly escaped to mitigate potential XSS risks.

Key Concerns

  • Significant unescaped output detected
  • Vulnerability history includes past CSRF
  • No capability checks on any entry points
Vulnerabilities
1

EZ Related Posts Footer Links and Widget Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-47514medium · 6.1Cross-Site Request Forgery (CSRF)

ELI's Related Posts Footer Links and Widget <= 1.2.04.20 - Cross-Site Request Forgery to Stored Cross-Site Scripting

May 7, 2025 Patched in 1.2.04.25 (7d)
Code Analysis
Analyzed Mar 16, 2026

EZ Related Posts Footer Links and Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
8 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

53% escaped15 total outputs
Attack Surface

EZ Related Posts Footer Links and Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterthe_contentindex.php:287
filterplugin_row_metaindex.php:560
filterplugin_action_linksindex.php:561
filterthe_contentindex.php:567
actionwidgets_initindex.php:569
actionadmin_menuindex.php:570
actionwpindex.php:571
Maintenance & Trust

EZ Related Posts Footer Links and Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 28, 2025
PHP min version
Downloads51K

Community Trust

Rating100/100
Number of ratings5
Active installs200
Developer Profile

EZ Related Posts Footer Links and Widget Developer Profile

Eli

9 plugins · 101K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
782 days
View full developer profile
Detection Fingerprints

How We Detect EZ Related Posts Footer Links and Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
rounded-cornersshadowed-boxsidebar-boxsidebar-linksshadowed-textsub-optioninsidepp_left+2 more
Data Attributes
id="right-sidebar"class="shadowed-box stuffbox"id="pluginlinks"name="submit"alt="Make a Donation with PayPal"name="submitc"+10 more
JS Globals
SPOSTARBUST_plugin_dirSPOSTARBUST_plugin_home
FAQ

Frequently Asked Questions about EZ Related Posts Footer Links and Widget