
ZK Advanced Feature Post Security & Risk Analysis
wordpress.org/plugins/zk-advanced-feature-postAJAX feature post function for your wordpress. Especially you can get featured post for custom category only.
Is ZK Advanced Feature Post Safe to Use in 2026?
Generally Safe
Score 85/100ZK Advanced Feature Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "zk-advanced-feature-post" v1.8.21 presents a significant security risk primarily due to its unprotected AJAX handler. With only one entry point identified and that single point lacking any authentication or capability checks, it creates a wide-open door for unauthenticated attackers. While the plugin shows good practices in other areas, such as using prepared statements for SQL queries and not performing file operations or external HTTP requests, the absence of authorization on its sole AJAX endpoint is a critical oversight. Furthermore, the low percentage of properly escaped output suggests a high likelihood of cross-site scripting (XSS) vulnerabilities being present, as data is likely being outputted directly into the browser without sufficient sanitization.
The vulnerability history being clear of known CVEs is a positive sign, implying that past versions may have been relatively secure or that the plugin is not a frequent target. However, this does not negate the immediate risks identified in the static analysis. The presence of a dangerous function like `create_function` is concerning as it can lead to code injection if not handled with extreme care, though its impact is lessened by the absence of taint flow analysis data. In conclusion, while the plugin demonstrates some positive security attributes, the lack of authorization on its AJAX endpoint and the poor output escaping practices create a weak security posture, making it highly susceptible to attacks.
Key Concerns
- Unprotected AJAX handler
- Missing Nonce checks on AJAX
- Low percentage of properly escaped output
- Use of dangerous function (create_function)
- Missing capability checks
ZK Advanced Feature Post Security Vulnerabilities
ZK Advanced Feature Post Code Analysis
Dangerous Functions Found
Output Escaping
ZK Advanced Feature Post Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
ZK Advanced Feature Post Maintenance & Trust
Maintenance Signals
Community Trust
ZK Advanced Feature Post Alternatives
Yet Another Featured Posts Plugin (YAFPP)
yet-another-featured-posts-plugin
Yet Another Featured Posts Plugin provides an easy AJAX interface to feature posts, with thumbnails & other display options for featured posts.
Nelio Featured Posts
nelio-featured-posts
Select the featured posts you want to show at any time and include them in your theme using a widget.
Featured Today
featured-today
Featured Today shows featured articles like it is shown on linkedin today.
Featured Post Creative
featured-post-creative
Display Featured post on your website with 2 shortcode and 1 widget. Also work with Gutenberg shortcode block.
Mark Posts
mark-posts
Mark and highlight posts, pages and posts of custom post types within the posts overview.
ZK Advanced Feature Post Developer Profile
1 plugin · 10 total installs
How We Detect ZK Advanced Feature Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zk-advanced-feature-post/css/style.css/wp-content/plugins/zk-advanced-feature-post/js/zk-admin-ajax.js/wp-content/plugins/zk-advanced-feature-post/img/no_thumb.png/wp-content/plugins/zk-advanced-feature-post/js/zk-admin-ajax.jszk-advanced-feature-post/css/style.css?ver=zk-advanced-feature-post/js/zk-admin-ajax.js?ver=HTML / DOM Fingerprints
zk-afpzkafp_onzkafp_offimgborderlink-onlythumb-onlyexceprtid="zkafp_all_id="zkafp_cat_onclick="zkafp_admin_ajax(zk-afpzkafp_admin_ajax<ul class="zk-afp">