
Widgets of Posts by Same Categories Security & Risk Analysis
wordpress.org/plugins/widgets-of-posts-by-same-categoriesThe widget area lists posts of the same category as the current post.
Is Widgets of Posts by Same Categories Safe to Use in 2026?
Generally Safe
Score 85/100Widgets of Posts by Same Categories has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "widgets-of-posts-by-same-categories" plugin v1.0.2 exhibits a generally good security posture in several key areas. Notably, there are no known vulnerabilities (CVEs) recorded, which is a strong indicator of a well-maintained and secure codebase. The absence of a significant attack surface, with zero entry points identified, further reduces the potential for external exploitation. All SQL queries are correctly prepared, and there are no file operations or external HTTP requests, mitigating common web application vulnerabilities.
However, the static analysis does reveal some significant concerns. The presence of the `create_function` function, considered dangerous due to its potential for arbitrary code execution, is a critical finding. Furthermore, a substantial portion of output is not properly escaped (only 18%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of any nonce or capability checks on the identified entry points (though there are zero, this still points to a lack of defensive programming) is also a weakness that could be exploited if new entry points were introduced without proper security measures.
While the plugin's vulnerability history is clean, this is offset by the immediate risks identified in the code. The use of `create_function` and the poor output escaping are actionable security flaws that require immediate attention. The plugin's strengths lie in its limited attack surface and secure SQL handling, but these are overshadowed by the critical code-level risks present.
Key Concerns
- Use of dangerous function 'create_function'
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
Widgets of Posts by Same Categories Security Vulnerabilities
Widgets of Posts by Same Categories Code Analysis
Dangerous Functions Found
Output Escaping
Widgets of Posts by Same Categories Attack Surface
WordPress Hooks 1
Maintenance & Trust
Widgets of Posts by Same Categories Maintenance & Trust
Maintenance Signals
Community Trust
Widgets of Posts by Same Categories Alternatives
Related Posts by Category Widget
related-posts-by-category-widget
Customizable widget area that displays posts from the same categories as the current post.
Social LikeBox & Feed
facebook-by-weblizar
Display your FaceBook Feed and Like box on your website with this outstanding plugin. It is completely customizable, responsive and the code is search …
Custom Related Posts
custom-related-posts
Manual related posts without slowing down your website!
Gabfire Widget Pack
gabfire-widget-pack
The Gabfire Widget Pack contains over a dozen useful widgets to extend your WordPress site. It is a free plugin that will work with ANY theme.
Related Posts Widget
related-posts-widget
Adds a widget that shows posts related to the current post based on tags.
Widgets of Posts by Same Categories Developer Profile
1 plugin · 70 total installs
How We Detect Widgets of Posts by Same Categories
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/widgets-of-posts-by-same-categories/widgets-of-posts-by-same-categories.phpHTML / DOM Fingerprints
widgets_of_posts_by_same_categoriesid="widgets_of_posts_by_same_categories"name="widgets_of_posts_by_same_categories"id="of_posts_by_same_categories"