
Trending/Popular Post Slider and Widget Security & Risk Analysis
wordpress.org/plugins/wp-trending-post-slider-and-widgetA quick, easy way to add Popular/Trending posts slider, grid block and widget. Also work with Gutenberg shortcode block.
Is Trending/Popular Post Slider and Widget Safe to Use in 2026?
Generally Safe
Score 100/100Trending/Popular Post Slider and Widget has a strong security track record. Known vulnerabilities have been patched promptly.
The 'wp-trending-post-slider-and-widget' plugin, version 1.8.6, presents a mixed security posture. On the positive side, it demonstrates good practices such as utilizing prepared statements for all SQL queries, implementing a significant number of nonce and capability checks, and maintaining a relatively low overall attack surface with no unprotected entry points identified in the static analysis. The high percentage of properly escaped output is also a strong indicator of secure development.
However, there are some areas of concern. The presence of the `unserialize` function is a critical signal, as it can be a vector for Remote Code Execution (RCE) if not handled with extreme caution and proper input validation. While no taint flows with unsanitized paths were found in this static analysis, the potential for an attacker to manipulate serialized data passed to `unserialize` remains a significant risk.
The vulnerability history shows a single medium-severity CVE, which is currently patched. This indicates that the plugin has had past security weaknesses, and while the immediate risk from this specific CVE is mitigated, it suggests a pattern of past vulnerabilities that warrants continued vigilance. The fact that the last vulnerability was in March 2023 and is now patched is a good sign of ongoing maintenance, but the presence of `unserialize` coupled with past CVEs elevates the overall risk profile.
Key Concerns
- Use of unserialize function
- Past medium severity CVE
Trending/Popular Post Slider and Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Trending/Popular Post Slider and Widget <= 1.5.7 - Cross-Site Request Forgery via wtpsw_post_view_count
Trending/Popular Post Slider and Widget Code Analysis
Dangerous Functions Found
Output Escaping
Trending/Popular Post Slider and Widget Attack Surface
AJAX Handlers 2
Shortcodes 3
WordPress Hooks 34
Scheduled Events 1
Maintenance & Trust
Trending/Popular Post Slider and Widget Maintenance & Trust
Maintenance Signals
Community Trust
Trending/Popular Post Slider and Widget Alternatives
No alternatives data available yet.
Trending/Popular Post Slider and Widget Developer Profile
33 plugins · 205K total installs
How We Detect Trending/Popular Post Slider and Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-trending-post-slider-and-widget/assets/css/wtpsw-public.css/wp-content/plugins/wp-trending-post-slider-and-widget/assets/css/slick.css/wp-content/plugins/wp-trending-post-slider-and-widget/assets/css/slick-theme.css/wp-content/plugins/wp-trending-post-slider-and-widget/assets/js/wtpsw-public.js/wp-content/plugins/wp-trending-post-slider-and-widget/assets/js/slick.min.js/wp-content/plugins/wp-trending-post-slider-and-widget/assets/js/public.jswp-trending-post-slider-and-widget/assets/css/wtpsw-public.css?ver=wp-trending-post-slider-and-widget/assets/css/slick.css?ver=wp-trending-post-slider-and-widget/assets/css/slick-theme.css?ver=wp-trending-post-slider-and-widget/assets/js/wtpsw-public.js?ver=wp-trending-post-slider-and-widget/assets/js/slick.min.js?ver=wp-trending-post-slider-and-widget/assets/js/public.js?ver=HTML / DOM Fingerprints
wtpsw-slider-wrapwtpsw-sliderwtpsw-grid-wrapwtpsw-gridboxwtpsw-carousel-wrapwtpsw-carouselwtpsw-post-list-widget<!-- start: wp trending post slider widget --><!-- // end: wp trending post slider widget --><!-- start: wp trending post grid box --><!-- // end: wp trending post grid box -->+4 moredata-settingswtpsw_data[wtpsw_slider][wtpsw_gridbox][wtpsw_carousel][wtpsw_post_list]