
Yet Another Featured Posts Plugin (YAFPP) Security & Risk Analysis
wordpress.org/plugins/yet-another-featured-posts-pluginYet Another Featured Posts Plugin provides an easy AJAX interface to feature posts, with thumbnails & other display options for featured posts.
Is Yet Another Featured Posts Plugin (YAFPP) Safe to Use in 2026?
Generally Safe
Score 85/100Yet Another Featured Posts Plugin (YAFPP) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of 'yet-another-featured-posts-plugin' v1.4 reveals a significant security concern with an unprotected AJAX handler. While the plugin demonstrates good practices in other areas, such as the absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and no reported vulnerabilities in its history, the unprotected entry point is a critical weakness. This means that any unauthenticated user could potentially trigger this AJAX action, opening the door to various exploits depending on its functionality. The lack of nonce checks and capability checks on this handler further exacerbates the risk. Despite the plugin's clean vulnerability history and its proper handling of SQL queries and external requests, the presence of an unprotected AJAX endpoint significantly lowers its overall security posture. The 0% output escaping is also a concern that could lead to cross-site scripting (XSS) vulnerabilities, though this is not explicitly confirmed by taint analysis in the provided data.
Key Concerns
- Unprotected AJAX handler
- Missing nonce checks
- Missing capability checks
- Output escaping 0%
Yet Another Featured Posts Plugin (YAFPP) Security Vulnerabilities
Yet Another Featured Posts Plugin (YAFPP) Code Analysis
Output Escaping
Yet Another Featured Posts Plugin (YAFPP) Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
Yet Another Featured Posts Plugin (YAFPP) Maintenance & Trust
Maintenance Signals
Community Trust
Yet Another Featured Posts Plugin (YAFPP) Alternatives
ZK Advanced Feature Post
zk-advanced-feature-post
AJAX feature post function for your wordpress. Especially you can get featured post for custom category only.
Nelio Featured Posts
nelio-featured-posts
Select the featured posts you want to show at any time and include them in your theme using a widget.
Featured Today
featured-today
Featured Today shows featured articles like it is shown on linkedin today.
Featured Post Creative
featured-post-creative
Display Featured post on your website with 2 shortcode and 1 widget. Also work with Gutenberg shortcode block.
Mark Posts
mark-posts
Mark and highlight posts, pages and posts of custom post types within the posts overview.
Yet Another Featured Posts Plugin (YAFPP) Developer Profile
1 plugin · 100 total installs
How We Detect Yet Another Featured Posts Plugin (YAFPP)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yet-another-featured-posts-plugin/yafpp.css/wp-content/plugins/yet-another-featured-posts-plugin/yafpp.jsHTML / DOM Fingerprints
yafpp-img