(a) RSS More Security & Risk Analysis

wordpress.org/plugins/a-rss-more

This is a plugin that allows you to additionally export RSS with the full text of the articles. Your reader can now select what RSS he wants to read h …

10 active installs v0.0.2 PHP + WP 3.0.0+ Updated Oct 20, 2010
feedrss
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is (a) RSS More Safe to Use in 2026?

Generally Safe

Score 85/100

(a) RSS More has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The plugin "a-rss-more" v0.0.2 demonstrates a generally good security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface, and importantly, there are no entry points found without authentication checks.

Code analysis reveals a positive sign with 100% of SQL queries utilizing prepared statements, indicating a commitment to preventing SQL injection. However, the fact that only 50% of output is properly escaped is a notable concern, suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities if sensitive data is displayed without adequate sanitization.

The plugin has no recorded vulnerability history, including CVEs. This lack of past issues, coupled with the limited attack surface and proper SQL handling, suggests a relatively safe plugin. Nevertheless, the potential for XSS due to insufficient output escaping is the primary area of concern. The plugin's strengths lie in its minimal attack surface and secure database interaction, while its weakness is the inconsistent handling of output sanitization.

Key Concerns

  • Half of output is not properly escaped
Vulnerabilities
None known

(a) RSS More Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

(a) RSS More Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

(a) RSS More Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Attack Surface

(a) RSS More Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filterthe_content_feeda-rss-more.php:35
filterquery_varsa-rss-more.php:36
actiontemplate_redirecta-rss-more.php:38
actionwp_heada-rss-more.php:39
actionadmin_menua-rss-more.php:41
filterwhitelist_optionsa-rss-more.php:83
Maintenance & Trust

(a) RSS More Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.0
Last updatedOct 20, 2010
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

(a) RSS More Developer Profile

antonshevchuk

3 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect (a) RSS More

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
name="rssopt_announce_rss_link"id="rssopt_announce_rss_link"name="rssopt_announce_feed_name"id="rssopt_announce_feed_name"name="rssopt_more_link_text"id="rssopt_more_link_text"+1 more
FAQ

Frequently Asked Questions about (a) RSS More