
WAD Recent Posts Security & Risk Analysis
wordpress.org/plugins/wad-recent-postsSimple and clean widget for showing recent posts list. It also has shortcode feature.
Is WAD Recent Posts Safe to Use in 2026?
Generally Safe
Score 85/100WAD Recent Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wad-recent-posts" plugin version 1.0.4 exhibits a generally positive security posture based on the provided static analysis. The absence of any recorded CVEs, coupled with no identified critical or high severity issues in taint analysis, suggests a strong adherence to secure coding practices historically. The code signals are also promising, with no dangerous functions or file operations, and all SQL queries utilizing prepared statements. The limited attack surface, consisting of a single shortcode with no identified unauthenticated entry points, further contributes to a good security outlook.
However, there are some areas for improvement. The most significant concern is the output escaping, where only 57% of outputs are properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not consistently sanitized before being displayed. Additionally, the complete absence of nonce checks and capability checks across all entry points is a notable weakness. While the attack surface is small, these missing security controls leave the plugin susceptible to certain types of attacks, especially if an attacker can trigger the shortcode under specific circumstances.
In conclusion, "wad-recent-posts" v1.0.4 has a solid foundation with a clean vulnerability history and good practices in areas like SQL querying and avoiding dangerous functions. The primary risks stem from the less-than-ideal output escaping and the lack of fundamental security checks like nonces and capability checks. Addressing these specific areas would significantly enhance the plugin's overall security.
Key Concerns
- Less than ideal output escaping
- Missing nonce checks
- Missing capability checks
WAD Recent Posts Security Vulnerabilities
WAD Recent Posts Code Analysis
Output Escaping
WAD Recent Posts Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
WAD Recent Posts Maintenance & Trust
Maintenance Signals
Community Trust
WAD Recent Posts Alternatives
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Simple Recent Posts Widget
simple-recent-posts-widget
Simple way to displaying your recent posts sidebar, including thumbnails, category, and number options.
Smart Recent Posts Widget
smart-recent-posts-widget
Provides advanced recent posts widget,you can display it with thumbnails, excerpt, date, author, comment count and more.
Recent Post Widget Thumbnail
recent-post-widget-thumbnail
Gives adaptable and highly organized recent posts. Show it through widget with thumbnails, post excerpt, post date.
Latest Posts With Thumbnails and Ads
latest-posts-with-thumbnails-and-ads
Just like the default Recent Posts widget except that posts are with thumbnails and you can show ads between them, show post date and comments count.
WAD Recent Posts Developer Profile
1 plugin · 0 total installs
How We Detect WAD Recent Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wad-recent-posts/css/wad-recent-posts.css/wp-content/plugins/wad-recent-posts/js/wad-recent-posts.js/wp-content/plugins/wad-recent-posts/js/wad-recent-posts.jswad-recent-posts/css/wad-recent-posts.css?ver=wad-recent-posts/js/wad-recent-posts.js?ver=HTML / DOM Fingerprints
id="wad_recent_posts"<div style="display: table; width: 100%; table-layout: fixed; margin-bottom: 10px;"><div style="display: table-cell; width: 92px; background: url(<div style="display: table-cell; text-align: left; padding-left: 10px;"><h3 style="font-size: 16px; margin: 0px;">