
WP Latest Posts Security & Risk Analysis
wordpress.org/plugins/wp-latest-postsLoad your content from posts, page, tags or custom post type and display it anywhere in WordPress including in Gutenberg editor
Is WP Latest Posts Safe to Use in 2026?
Generally Safe
Score 99/100WP Latest Posts has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-latest-posts plugin, version 5.0.11, exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, a high percentage of properly escaped output, and a substantial number of nonce and capability checks. The plugin also has no bundled libraries, which can reduce the attack surface associated with outdated dependencies. However, there are significant areas of concern. The presence of 3 AJAX handlers without authentication checks presents a notable attack vector, as does the use of the dangerous 'exec' function, even if its usage context isn't detailed. The single taint flow with an unsanitized path is also a red flag, indicating a potential for input manipulation vulnerabilities, although it's not categorized as critical or high. The plugin's vulnerability history shows a pattern of medium severity issues related to code injection and cross-site scripting, with the most recent occurring in May 2024. While there are no currently unpatched vulnerabilities, this history suggests a recurring need for careful code review and patching. Overall, the plugin has strengths in its data handling but weaknesses in input validation for its AJAX endpoints and the inclusion of potentially dangerous functions.
Key Concerns
- AJAX handlers without authentication checks
- Presence of dangerous 'exec' function
- Taint flow with unsanitized paths
- Medium severity vulnerabilities in history
WP Latest Posts Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Latest Posts <= 5.0.7 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
WP Latest Posts <= 3.7.4 - Reflected Cross-Site Scripting
WP Latest Posts Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Latest Posts Attack Surface
AJAX Handlers 9
Shortcodes 3
WordPress Hooks 68
Scheduled Events 1
Maintenance & Trust
WP Latest Posts Maintenance & Trust
Maintenance Signals
Community Trust
WP Latest Posts Alternatives
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts
post-carousel
Display posts, pages, and taxonomies in beautiful carousel, slider, and grid layouts with advanced filtering. Customizable, Developer-friendly.
PE Recent Posts
pe-recent-posts
The simple plugin that allows you to display image slides with title, description and read more linked to posts from selected category.
Enhanced Recent Posts
enhanced-recent-posts
Enhance the built-in "Recent Posts" widget.
Latest Posts Widget
latest-posts-widget
Adds a widget that shows the most recent posts of your site with excerpt, featured image, date by sorting & ordering feature
Recent Posts Shortcode & Widget
recent-posts-shortcode-widget
Display list of recent posts and latest posts or random posts using the [recentposts-sc] shortcode in any page or in sidebar widgets.
WP Latest Posts Developer Profile
3 plugins · 27K total installs
How We Detect WP Latest Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-latest-posts/css/divi-widgets.css/wp-content/plugins/wp-latest-posts/js/imagesloaded.pkgd.min.js/wp-content/plugins/wp-latest-posts/themes/default/style.css/wp-content/plugins/wp-latest-posts/js/flexslider.min.js/wp-content/plugins/wp-latest-posts/js/swiper-bundle.min.js/wp-content/plugins/wp-latest-posts/js/wplp_front.jswp-content/plugins/wp-latest-posts/js/imagesloaded.pkgd.min.jswp-content/plugins/wp-latest-posts/js/flexslider.min.jswp-content/plugins/wp-latest-posts/js/swiper-bundle.min.jswp-content/plugins/wp-latest-posts/js/wplp_front.jswp-latest-posts/css/divi-widgets.css?ver=wp-latest-posts/js/imagesloaded.pkgd.min.js?ver=wp-latest-posts/themes/default/style.css?ver=wp-latest-posts/js/flexslider.min.js?ver=wp-latest-posts/js/swiper-bundle.min.js?ver=wp-latest-posts/js/wplp_front.js?ver=HTML / DOM Fingerprints
wplp-sliderwplp-flex-sliderwplp-isotope-containerwplp-category-iconwplp-post-thumbnailwplp-post-titlewplp-post-datewplp-post-author+3 moredata-wplp-slider-iddata-wplp-optionswplp_params[wp_latest_posts]