
WP Recently Viewed Security & Risk Analysis
wordpress.org/plugins/wp-recently-viewedLet visitors see there recently view post. 讓訪客查看他們最近訪問過的文章
Is WP Recently Viewed Safe to Use in 2026?
Generally Safe
Score 100/100WP Recently Viewed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The `wp-recently-viewed` plugin version 1.0 presents a generally positive security posture based on the provided static analysis and vulnerability history. The absence of AJAX handlers, REST API routes, shortcodes, cron events, and file operations significantly limits the plugin's attack surface. Furthermore, the fact that all SQL queries utilize prepared statements and there are no recorded CVEs is a strong indicator of secure development practices for this version.
However, a notable concern arises from the low percentage (13%) of properly escaped output. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, as unsanitized output can be injected into the user's browser. The lack of nonce and capability checks, while not directly leading to specific vulnerabilities in this static analysis, indicates a missed opportunity to enforce proper authorization and integrity on potential (even if currently non-existent) entry points.
In conclusion, while `wp-recently-viewed` v1.0 benefits from a minimal attack surface and robust SQL handling, the insufficient output escaping is a significant weakness that requires attention. The absence of historical vulnerabilities is a good sign, but the current code analysis highlights a specific area that could be exploited. Developers should prioritize addressing the unescaped output to improve the plugin's overall security.
Key Concerns
- Low output escaping percentage
- No nonce checks
- No capability checks
WP Recently Viewed Security Vulnerabilities
WP Recently Viewed Code Analysis
Output Escaping
WP Recently Viewed Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP Recently Viewed Maintenance & Trust
Maintenance Signals
Community Trust
WP Recently Viewed Alternatives
Recently Viewed Product for WooCommerce
recently-viewed-products-for-woocommerce
Recently Viewed Products for WooCommerce Listing page, you can easily add recently viewed product section by activate the plugin.
Posts Viewed Recently
posts-viewed-recently
Posts Viewed Recently plugin shows recently viewed posts or pages by a visitor as a responsive sidebar widget or on a page/post using the shortcode.
DD Last Viewed
dd-lastviewed
Shows the users recently viewed/visited posts, filtered on types or terms, in a widget.
Last Viewed Posts by WPBeginner
last-viewed-posts
This shows your site's visitors a personalized list of posts and pages they have recently viewed.
MATE Recently Viewed Products – Cache Compatible for WooCommerce
mate-recently-viewed-products
Display recently viewed WooCommerce products via AJAX and cookies. Works with caching. Includes a customizable block and shortcode.
WP Recently Viewed Developer Profile
24 plugins · 2K total installs
How We Detect WP Recently Viewed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-recently-viewed/js/view-history.js/wp-content/plugins/wp-recently-viewed/js/add-history.js/wp-content/plugins/wp-recently-viewed/js/view-history.js/wp-content/plugins/wp-recently-viewed/js/add-history.jsHTML / DOM Fingerprints
wp_recently_viewed_classwp-recently-viewed