
WZ Followed Posts – Display what visitors are reading Security & Risk Analysis
wordpress.org/plugins/where-did-they-go-from-hereShow "Readers who viewed this page, also viewed" a.k.a. followed posts on your page. Much like Amazon.com's product pages.
Is WZ Followed Posts – Display what visitors are reading Safe to Use in 2026?
Generally Safe
Score 99/100WZ Followed Posts – Display what visitors are reading has a strong security track record. Known vulnerabilities have been patched promptly.
The "where-did-they-go-from-here" plugin v3.1.2 exhibits a generally strong security posture based on the static analysis. The presence of nonce and capability checks on all identified entry points is a significant positive, indicating a good understanding of WordPress security best practices. The high percentage of properly escaped output and the use of prepared statements for the majority of SQL queries further bolster its security. The absence of critical or high severity taint flows is also reassuring.
However, there are a few areas that warrant attention. While the static analysis reports zero unprotected entry points, it's worth noting the presence of 5 AJAX handlers, which, even with checks, represent potential vectors if the checks are not robust or have implementation flaws. The history of one medium severity CVE, specifically Cross-Site Scripting, although patched, suggests that input sanitization and output escaping might have had past weaknesses that, while addressed, serve as a reminder for ongoing vigilance. The single file operation, while not inherently risky, should always be scrutinized for potential path traversal or unauthorized access vulnerabilities.
Overall, the plugin demonstrates good security development habits, particularly in its handling of entry points and data output. The past vulnerability, while concerning, has been addressed. Continuous monitoring and periodic security audits are recommended to maintain this favorable security profile and prevent recurrence of past issues.
Key Concerns
- Past medium CVE for XSS
WZ Followed Posts – Display what visitors are reading Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WZ Followed Posts – Display what visitors are reading <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
WZ Followed Posts – Display what visitors are reading Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WZ Followed Posts – Display what visitors are reading Attack Surface
AJAX Handlers 5
Shortcodes 2
WordPress Hooks 41
Maintenance & Trust
WZ Followed Posts – Display what visitors are reading Maintenance & Trust
Maintenance Signals
Community Trust
WZ Followed Posts – Display what visitors are reading Alternatives
Inline Related Posts
intelly-related-posts
Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
YARPP – Yet Another Related Posts Plugin
yet-another-related-posts-plugin
The best WordPress plugin for displaying related posts. Simple and flexible, with a powerful proven algorithm and inbuilt caching.
Contextual Related Posts
contextual-related-posts
Keep visitors on your site longer with intelligent, fast-loading, contextually related posts. Block, shortcode, custom post type and widget ready.
Related Posts for WordPress
related-posts-for-wp
The best WordPress plugin for related posts. Simple, flexible, powerful algorithm, and built-in caching. Fully setup with only 1 click!
WZ Followed Posts – Display what visitors are reading Developer Profile
31 plugins · 89K total installs
How We Detect WZ Followed Posts – Display what visitors are reading
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/where-did-they-go-from-here/assets/css/wz-frontend.css/wp-content/plugins/where-did-they-go-from-here/assets/js/wz-frontend.js/wp-content/plugins/where-did-they-go-from-here/assets/js/wz-frontend.jswhere-did-they-go-from-here/assets/css/wz-frontend.css?ver=where-did-they-go-from-here/assets/js/wz-frontend.js?ver=HTML / DOM Fingerprints
wherego-followed-postswz-followed-posts-listdata-wherego-post-iddata-wherego-post-typewherego_admin_data[followed_posts][followedposts]