
WP Featured News – Custom Posts Listing Elements Security & Risk Analysis
wordpress.org/plugins/wp-featured-news-custom-posts-listing-elementsWP Featured News plugin allows you to display your posts anywhere of your web-pages with 10 powerful and creatively designed post blocks.
Is WP Featured News – Custom Posts Listing Elements Safe to Use in 2026?
Generally Safe
Score 100/100WP Featured News – Custom Posts Listing Elements has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
This plugin, wp-featured-news-custom-posts-listing-elements v2.0.0, exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and a high percentage of properly escaped output are commendable security practices. Furthermore, the lack of external HTTP requests and file operations reduces potential attack vectors. The plugin also demonstrates an understanding of WordPress security by performing capability checks.
However, the analysis does highlight a significant concern: the complete absence of nonce checks across all identified entry points, which include 10 shortcodes. While there are no unprotected AJAX handlers or REST API routes, the shortcodes represent a substantial attack surface that lacks this crucial security mechanism. The taint analysis results are clean, indicating no identified vulnerabilities through that specific method, and the plugin has no historical CVEs, which is a positive indicator.
In conclusion, while the plugin has strengths in its handling of sensitive functions and data operations, the lack of nonce validation on its shortcodes presents a notable weakness. This could potentially lead to Cross-Site Request Forgery (CSRF) attacks if shortcodes are designed to perform sensitive actions. The absence of past vulnerabilities is encouraging, but it does not mitigate the current risk posed by the missing nonce checks.
Key Concerns
- Missing nonce checks on shortcodes
WP Featured News – Custom Posts Listing Elements Security Vulnerabilities
WP Featured News – Custom Posts Listing Elements Code Analysis
Output Escaping
WP Featured News – Custom Posts Listing Elements Attack Surface
Shortcodes 10
WordPress Hooks 17
Maintenance & Trust
WP Featured News – Custom Posts Listing Elements Maintenance & Trust
Maintenance Signals
Community Trust
WP Featured News – Custom Posts Listing Elements Alternatives
Featured Posts Widget
olympus-featured-posts-widget
Add a selection of posts to your sidebar or another widget location.
Latest News Widget
latest-news-widget
A customizable latest news widget.
CCR Featured Posts
ccr-featured-posts
Featured Posts Widget shows by selected categories
Launchpad Popular Posts
launchpad-popular-posts
This is a very simple, easy to use plugin which creates a widget that can be used to display Popular Posts, Related Posts, Featured Posts, Recent Post …
Olympus Widgets
olympus-widgets
Adds eight new widgets you can use in your sidebar.
WP Featured News – Custom Posts Listing Elements Developer Profile
2 plugins · 100 total installs
How We Detect WP Featured News – Custom Posts Listing Elements
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-featured-news-custom-posts-listing-elements/js/wfnews-admin-js.js/wp-content/plugins/wp-featured-news-custom-posts-listing-elements/css/wfnews-admin-style.css/wp-content/plugins/wp-featured-news-custom-posts-listing-elements/js/wfnews-admin-js.jswfnews-admin-js.js?ver=wfnews-admin-style.css?ver=HTML / DOM Fingerprints
panto-page-welcomevc-page-logoWFNEWS_PLUGIN_VERSION