WP Featured News – Custom Posts Listing Elements Security & Risk Analysis

wordpress.org/plugins/wp-featured-news-custom-posts-listing-elements

WP Featured News plugin allows you to display your posts anywhere of your web-pages with 10 powerful and creatively designed post blocks.

10 active installs v2.0.0 PHP 7.4+ WP 5.9+ Updated Nov 2, 2025
custom-post-typesfeatured-postsfeatured-posts-widgetpopular-posts-widgetposts-list-widget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Featured News – Custom Posts Listing Elements Safe to Use in 2026?

Generally Safe

Score 100/100

WP Featured News – Custom Posts Listing Elements has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

This plugin, wp-featured-news-custom-posts-listing-elements v2.0.0, exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and a high percentage of properly escaped output are commendable security practices. Furthermore, the lack of external HTTP requests and file operations reduces potential attack vectors. The plugin also demonstrates an understanding of WordPress security by performing capability checks.

However, the analysis does highlight a significant concern: the complete absence of nonce checks across all identified entry points, which include 10 shortcodes. While there are no unprotected AJAX handlers or REST API routes, the shortcodes represent a substantial attack surface that lacks this crucial security mechanism. The taint analysis results are clean, indicating no identified vulnerabilities through that specific method, and the plugin has no historical CVEs, which is a positive indicator.

In conclusion, while the plugin has strengths in its handling of sensitive functions and data operations, the lack of nonce validation on its shortcodes presents a notable weakness. This could potentially lead to Cross-Site Request Forgery (CSRF) attacks if shortcodes are designed to perform sensitive actions. The absence of past vulnerabilities is encouraging, but it does not mitigate the current risk posed by the missing nonce checks.

Key Concerns

  • Missing nonce checks on shortcodes
Vulnerabilities
None known

WP Featured News – Custom Posts Listing Elements Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP Featured News – Custom Posts Listing Elements Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
244 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped247 total outputs
Attack Surface

WP Featured News – Custom Posts Listing Elements Attack Surface

Entry Points10
Unprotected0

Shortcodes 10

[wfnews_post_block_1_post] modules\p1\shortcodes.php:490
[wfnews_post_block_10_post] modules\p10\shortcodes.php:336
[wfnews_post_block_2_post] modules\p2\shortcodes.php:452
[wfnews_post_block_3_post] modules\p3\shortcodes.php:446
[wfnews_post_block_4_post] modules\p4\shortcodes.php:481
[wfnews_post_block_5_post] modules\p5\shortcodes.php:474
[wfnews_post_block_6_post] modules\p6\shortcodes.php:352
[wfnews_post_block_7_post] modules\p7\shortcodes.php:305
[wfnews_post_block_8_post] modules\p8\shortcodes.php:288
[wfnews_post_block_9_post] modules\p9\shortcodes.php:302
WordPress Hooks 17
actionadmin_enqueue_scriptsmodules\admin-functions.php:5
actionadmin_menumodules\admin-functions.php:11
actionwp_enqueue_scriptsmodules\inc\enqueue.php:3
actionwp_enqueue_scriptsmodules\inc\enqueue.php:62
actionwp_enqueue_scriptsmodules\inc\enqueue.php:74
actionwp_enqueue_scriptsmodules\inc\enqueue.php:92
actionwp_enqueue_scriptsmodules\inc\enqueue.php:103
actioninitmodules\p1\vc_shortcodes.php:5
actioninitmodules\p10\vc_shortcodes.php:5
actioninitmodules\p2\vc_shortcodes.php:5
actioninitmodules\p3\vc_shortcodes.php:5
actioninitmodules\p4\vc_shortcodes.php:5
actioninitmodules\p5\vc_shortcodes.php:5
actioninitmodules\p6\vc_shortcodes.php:5
actioninitmodules\p7\vc_shortcodes.php:5
actioninitmodules\p8\vc_shortcodes.php:5
actioninitmodules\p9\vc_shortcodes.php:5
Maintenance & Trust

WP Featured News – Custom Posts Listing Elements Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 2, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings5
Active installs10
Developer Profile

WP Featured News – Custom Posts Listing Elements Developer Profile

Fluent-Themes

2 plugins · 100 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Featured News – Custom Posts Listing Elements

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-featured-news-custom-posts-listing-elements/js/wfnews-admin-js.js/wp-content/plugins/wp-featured-news-custom-posts-listing-elements/css/wfnews-admin-style.css
Script Paths
/wp-content/plugins/wp-featured-news-custom-posts-listing-elements/js/wfnews-admin-js.js
Version Parameters
wfnews-admin-js.js?ver=wfnews-admin-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
panto-page-welcomevc-page-logo
JS Globals
WFNEWS_PLUGIN_VERSION
FAQ

Frequently Asked Questions about WP Featured News – Custom Posts Listing Elements