Yet Another Featured Posts Plugin (YAFPP) Security & Risk Analysis

wordpress.org/plugins/yet-another-featured-posts-plugin

Yet Another Featured Posts Plugin provides an easy AJAX interface to feature posts, with thumbnails & other display options for featured posts.

100 active installs v1.4 PHP + WP 2.8.4+ Updated Apr 23, 2010
featuredfeatured-postshighlightstarstarred
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Yet Another Featured Posts Plugin (YAFPP) Safe to Use in 2026?

Generally Safe

Score 85/100

Yet Another Featured Posts Plugin (YAFPP) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The static analysis of 'yet-another-featured-posts-plugin' v1.4 reveals a significant security concern with an unprotected AJAX handler. While the plugin demonstrates good practices in other areas, such as the absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and no reported vulnerabilities in its history, the unprotected entry point is a critical weakness. This means that any unauthenticated user could potentially trigger this AJAX action, opening the door to various exploits depending on its functionality. The lack of nonce checks and capability checks on this handler further exacerbates the risk. Despite the plugin's clean vulnerability history and its proper handling of SQL queries and external requests, the presence of an unprotected AJAX endpoint significantly lowers its overall security posture. The 0% output escaping is also a concern that could lead to cross-site scripting (XSS) vulnerabilities, though this is not explicitly confirmed by taint analysis in the provided data.

Key Concerns

  • Unprotected AJAX handler
  • Missing nonce checks
  • Missing capability checks
  • Output escaping 0%
Vulnerabilities
None known

Yet Another Featured Posts Plugin (YAFPP) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Yet Another Featured Posts Plugin (YAFPP) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface
1 unprotected

Yet Another Featured Posts Plugin (YAFPP) Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_yafpp_processyafpp.php:451
WordPress Hooks 10
filterexcerpt_lengthyafpp.php:66
actionadmin_menuyafpp.php:444
filtermanage_posts_columnsyafpp.php:447
filtermanage_posts_custom_columnyafpp.php:448
actionadmin_print_scriptsyafpp.php:452
actionadmin_headyafpp.php:453
filtermanage_pages_columnsyafpp.php:457
filtermanage_pages_custom_columnyafpp.php:458
filteryafpp_get_featured_posts_queryyafpp.php:459
filteryafpp_get_featured_posts_query_adminyafpp.php:460
Maintenance & Trust

Yet Another Featured Posts Plugin (YAFPP) Maintenance & Trust

Maintenance Signals

WordPress version tested2.9.2
Last updatedApr 23, 2010
PHP min version
Downloads31K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Yet Another Featured Posts Plugin (YAFPP) Developer Profile

JonRaasch

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Yet Another Featured Posts Plugin (YAFPP)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yet-another-featured-posts-plugin/yafpp.css/wp-content/plugins/yet-another-featured-posts-plugin/yafpp.js

HTML / DOM Fingerprints

CSS Classes
yafpp-img
FAQ

Frequently Asked Questions about Yet Another Featured Posts Plugin (YAFPP)