
Super recent posts Security & Risk Analysis
wordpress.org/plugins/super-recent-postsWidget that can display recent posts from multiple categories, taxonomies, terms custom post types.
Is Super recent posts Safe to Use in 2026?
Generally Safe
Score 85/100Super recent posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "super-recent-posts" v0.1 plugin exhibits significant security concerns due to its limited attack surface being entirely unprotected. The presence of an unprotected AJAX handler represents a direct entry point for potential attackers, especially since no nonce or capability checks are implemented. This lack of authentication on a critical entry point is a major weakness.
While the plugin utilizes prepared statements for its single SQL query, a substantial number of its outputs (90%) are not properly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the context of a user's browser. The taint analysis revealing three flows with unsanitized paths further reinforces the XSS concern, indicating that user-supplied data might be processed in an unsafe manner, potentially leading to code execution.
The plugin has no recorded vulnerability history, which is a positive indicator. However, the static analysis reveals fundamental security flaws that could be exploited regardless of past vulnerabilities. The use of `create_function` is also a deprecated and potentially insecure practice that should be avoided. Overall, the plugin has a weak security posture primarily due to its unprotected entry points and significant risk of XSS, despite its clean vulnerability history and safe SQL practices.
Key Concerns
- Unprotected AJAX handler
- Insufficient output escaping (high XSS risk)
- Flows with unsanitized paths
- Use of deprecated and unsafe create_function
- Missing nonce checks
- Missing capability checks
Super recent posts Security Vulnerabilities
Super recent posts Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Super recent posts Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
Super recent posts Maintenance & Trust
Maintenance Signals
Community Trust
Super recent posts Alternatives
Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor)
content-views-query-and-display-post-page
Easy to show posts, pages, custom posts in customizable grid, list, slider, accordion... Available as Widgets (for Elementor), Shortcode, and Blocks.
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Category Posts Widget
category-posts
Adds a widget that shows the most recent posts from a single category.
VK Link Target Controller
vk-link-target-controller
Redirect your visitors to another page than the post content when they click on the post title.
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts
post-carousel
Display posts, pages, and taxonomies in beautiful carousel, slider, and grid layouts with advanced filtering. Customizable, Developer-friendly.
Super recent posts Developer Profile
3 plugins · 170 total installs
How We Detect Super recent posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/super-recent-posts/css/style.css/wp-content/plugins/super-recent-posts/js/script.js/wp-content/plugins/super-recent-posts/timthumb/timthumb.php/wp-content/plugins/super-recent-posts/js/script.jssuper-recent-posts/css/style.css?ver=super-recent-posts/js/script.js?ver=HTML / DOM Fingerprints
super_recent_postssuper_recent_posts_itemsuper_recent_posts_item_titledata-srp-termsdata-srp-posttypesdata-srp-postsdata-srp-thumbnail_hdata-srp-thumbnail_wdata-srp-excerpt_length+3 moresuper_recent_posts_widget_ajax_object/wp-json/srp_api/v1/get_taxonomy_terms