
YD Featured Box Widget Security & Risk Analysis
wordpress.org/plugins/yd-featured-block-widgetQuick and simple featured boxes as widgets
Is YD Featured Box Widget Safe to Use in 2026?
Generally Safe
Score 85/100YD Featured Box Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The yd-featured-block-widget plugin v0.1.4 exhibits a generally good security posture with no known vulnerabilities or critical code signals. The absence of direct entry points like AJAX handlers, REST API routes, and shortcodes, coupled with the plugin's use of prepared statements for all SQL queries and the presence of nonce and capability checks, suggests a developer who is mindful of basic WordPress security principles. There are no dangerous functions or file operations detected, and no external HTTP requests are made, further contributing to a reduced attack surface.
However, the static analysis reveals a significant weakness in output escaping. With only 3% of 65 total outputs properly escaped, there is a high likelihood of cross-site scripting (XSS) vulnerabilities. While the taint analysis did not uncover critical or high-severity flows, the presence of one flow with an unsanitized path indicates a potential for indirect vulnerabilities that might be triggered under specific conditions, especially when combined with the poor output escaping. The plugin's vulnerability history being clean is a positive sign, but it doesn't negate the immediate risks identified in the code.
In conclusion, while the plugin benefits from a lack of known historical vulnerabilities and a seemingly secure foundational structure, the prevalent issue of insufficient output escaping presents a significant and actionable risk that requires immediate attention. Addressing this would greatly strengthen the plugin's overall security.
Key Concerns
- Poor output escaping (3%)
- Taint flow with unsanitized path
YD Featured Box Widget Security Vulnerabilities
YD Featured Box Widget Code Analysis
Output Escaping
Data Flow Analysis
YD Featured Box Widget Attack Surface
WordPress Hooks 5
Scheduled Events 2
Maintenance & Trust
YD Featured Box Widget Maintenance & Trust
Maintenance Signals
Community Trust
YD Featured Box Widget Alternatives
Featured Post Creative
featured-post-creative
Display Featured post on your website with 2 shortcode and 1 widget. Also work with Gutenberg shortcode block.
AK Featured Post Widget
akfeatured-post-widget
A widget that you can use to display your blog posts, custom post types, or woocommerce products!
Nelio Featured Posts
nelio-featured-posts
Select the featured posts you want to show at any time and include them in your theme using a widget.
Latest News Widget
latest-news-widget
A customizable latest news widget.
Featured Posts Pro
featured-posts-pro
This plugin gives Administrator/Editor an easy option to mark posts, pages & custom posts as featured posts and provides a widget to list the rece …
YD Featured Box Widget Developer Profile
14 plugins · 180 total installs
How We Detect YD Featured Box Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yd-featured-block-widget/css/yd_featured_box.cssyd-featured-block-widget/css/yd_featured_box.css?ver=HTML / DOM Fingerprints
yd_featured_boxydfb_imageydfb_text_topydfb_text_bottomonclick="location='class="yd_featured_box"href="src="title="alt="+3 more