
WPCT Drag & Drop Recent Posts Security & Risk Analysis
wordpress.org/plugins/wpct-drag-drop-recent-postsYou can display image slides with title, image, author name, date, description, and read more linked to posts from the selected category.
Is WPCT Drag & Drop Recent Posts Safe to Use in 2026?
Generally Safe
Score 85/100WPCT Drag & Drop Recent Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wpct-drag-drop-recent-posts" v1.11 presents a generally strong security posture based on the provided static analysis and vulnerability history. The absence of AJAX handlers, REST API routes, shortcodes, cron events, and file operations significantly limits the potential attack surface. Furthermore, the code employs prepared statements for all SQL queries and avoids external HTTP requests, which are excellent security practices. However, a critical concern arises from the extremely low percentage of properly escaped output. With 145 total outputs and only 1% being properly escaped, this indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. The lack of nonce and capability checks, while not directly problematic given the absence of entry points, means that if any entry points were to be introduced in the future, they would lack crucial authentication and authorization measures.
Key Concerns
- Poor output escaping
- Missing nonce checks
- Missing capability checks
WPCT Drag & Drop Recent Posts Security Vulnerabilities
WPCT Drag & Drop Recent Posts Release Timeline
WPCT Drag & Drop Recent Posts Code Analysis
Output Escaping
WPCT Drag & Drop Recent Posts Attack Surface
WordPress Hooks 5
Maintenance & Trust
WPCT Drag & Drop Recent Posts Maintenance & Trust
Maintenance Signals
Community Trust
WPCT Drag & Drop Recent Posts Alternatives
Widget Post Slider
widget-post-slider
Widget Post Slider to display posts image in a slider from category.
Latest Posts
latest-posts
Latest posts widget to display recent posts from category.
Latest News Widget
latest-news-widget
A customizable latest news widget.
Latest Posts Widget
latest-posts-widget
Adds a widget that shows the most recent posts of your site with excerpt, featured image, date by sorting & ordering feature
Custom latest posts widget
custom-latest-posts-widget
Improve your sidebar a widget that shows the most recent posts of your site with excerpt, featured image, post type
WPCT Drag & Drop Recent Posts Developer Profile
1 plugin · 0 total installs
How We Detect WPCT Drag & Drop Recent Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpct-drag-drop-recent-posts/css/slider.css/wp-content/plugins/wpct-drag-drop-recent-posts/js/slider.js/wp-content/plugins/wpct-drag-drop-recent-posts/js/slider.jswpct-drag-drop-recent-posts/css/slider.css?ver=wpct-drag-drop-recent-posts/js/slider.js?ver=HTML / DOM Fingerprints
WPCTrecentPostswpct-excerpt-textwpct-slider-container<!-- wp:wpct/recent-posts -->data-intervaldata-slider-pausedata-columnsdata-rowsdata-grid-spacingdata-navigation-way+20 morewpct_slider_config[wpct_recent_posts