Admin Dashboard RSS Feed Security & Risk Analysis

wordpress.org/plugins/admin-dashboard-rss-feed

Admin Dashboard RSS Feed displays company news in the WordPress Admin Dashboard using an RSS feed. It provides quick access to the latest updates.

500 active installs v3.8 PHP + WP 4.7.5+ Updated Apr 25, 2025
admin-widgetadmin-rss-feedrss-feedshow-rss-feedwordpress-admin-dashboard
99
A · Safe
CVEs total1
Unpatched0
Last CVEJul 11, 2024
Safety Verdict

Is Admin Dashboard RSS Feed Safe to Use in 2026?

Generally Safe

Score 99/100

Admin Dashboard RSS Feed has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jul 11, 2024Updated 11mo ago
Risk Assessment

The 'admin-dashboard-rss-feed' plugin version 3.8 exhibits a generally strong security posture based on the static analysis. The absence of an attack surface, dangerous functions, raw SQL queries, and file operations is commendable. Furthermore, the high percentage of properly escaped output and the presence of nonce checks suggest good development practices for handling user input and preventing common web vulnerabilities. The taint analysis revealing no flows with unsanitized paths further bolsters this positive assessment.

However, the plugin's vulnerability history introduces a significant concern. The presence of one known CVE, albeit currently patched, indicates that the plugin has been susceptible to vulnerabilities in the past. The previous occurrence of Cross-site Scripting (XSS) is particularly noteworthy. While the current version appears to have addressed these issues, the history suggests a potential for recurring vulnerabilities if code auditing and security testing are not consistently maintained. The lack of capability checks, while not a direct vulnerability in isolation given the zero attack surface, could become a risk if the attack surface were to expand in future versions without corresponding security measures.

In conclusion, version 3.8 of 'admin-dashboard-rss-feed' demonstrates a robust implementation with minimal apparent risks in its current code. The strengths lie in its clean code structure and diligent output escaping. The primary weakness remains the historical susceptibility to XSS, which, despite being patched, warrants continued vigilance for this plugin.

Key Concerns

  • Previous XSS vulnerability history
  • No capability checks found
Vulnerabilities
1

Admin Dashboard RSS Feed Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-38725medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Admin Dashboard RSS Feed <= 3.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jul 11, 2024 Patched in 3.5 (253d)
Code Analysis
Analyzed Mar 16, 2026

Admin Dashboard RSS Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
54 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped59 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
wsx_rss_feed_admin_settings (admin-rss-feed.php:100)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Admin Dashboard RSS Feed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_noticesadmin-rss-feed.php:34
actionadmin_menuadmin-rss-feed.php:67
actionadmin_initadmin-rss-feed.php:73
actionadmin_enqueue_scriptsadmin-rss-feed.php:99
actionwp_dashboard_setupadmin-rss-feed.php:205
Maintenance & Trust

Admin Dashboard RSS Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 25, 2025
PHP min version
Downloads20K

Community Trust

Rating100/100
Number of ratings1
Active installs500
Developer Profile

Admin Dashboard RSS Feed Developer Profile

wsxplugindev

4 plugins · 720 total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
253 days
View full developer profile
Detection Fingerprints

How We Detect Admin Dashboard RSS Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/admin-dashboard-rss-feed/admin/css/style.css/wp-content/plugins/admin-dashboard-rss-feed/admin/js/admin.js
Script Paths
/wp-content/plugins/admin-dashboard-rss-feed/admin/js/admin.js
Version Parameters
admin-dashboard-rss-feed/admin/css/style.css?ver=admin-dashboard-rss-feed/admin/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wsx-smallclsImagePreviewwsx-rss-feed-btn
Data Attributes
id="image-preview"id="upload_image_button"id="delete_image_button"id="image_attachment_id"name="wsx_logo_title"name="wsx_logo_target_link"+7 more
JS Globals
rssFeedVars
FAQ

Frequently Asked Questions about Admin Dashboard RSS Feed