Auto podcast import Security & Risk Analysis

wordpress.org/plugins/auto-podcast-import

Import your podcast feed, automatically from any supported podcast provider.

100 active installs v1.0.18 PHP 7.4+ WP 6.1.0+ Updated Mar 15, 2026
feedimportpodcastrsssync
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Auto podcast import Safe to Use in 2026?

Generally Safe

Score 100/100

Auto podcast import has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 20d ago
Risk Assessment

The "auto-podcast-import" plugin v1.0.18 exhibits a strong security posture in several key areas. The absence of any known vulnerabilities (CVEs) and the fact that all identified SQL queries utilize prepared statements are significant strengths. Furthermore, the plugin demonstrates good practices by incorporating nonce checks and capability checks within its code. The static analysis reveals a clean attack surface with no immediately identifiable entry points that lack authentication. The taint analysis also shows no critical or high-severity issues with unsanitized data flows.

However, a notable concern arises from the output escaping. With 139 total outputs and only 39% properly escaped, there is a significant potential for cross-site scripting (XSS) vulnerabilities. This means that untrusted data, if it finds its way into these unescaped outputs, could be rendered by the user's browser and executed as malicious code. While the plugin has no known CVEs and a seemingly limited attack surface from the static analysis perspective, the lack of robust output escaping presents a substantial, albeit latent, risk that needs to be addressed to improve its overall security.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Auto podcast import Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Auto podcast import Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
85
54 escaped
Nonce Checks
5
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

39% escaped139 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<admin_menu> (inc\admin_menu.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Auto podcast import Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuinc\admin_menu.php:32
filterwp_mail_content_typeinc\admin_menu.php:280
filterpost_thumbnail_idinc\filters.php:7
filterpost_thumbnail_htmlinc\filters.php:8
Maintenance & Trust

Auto podcast import Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 15, 2026
PHP min version7.4
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Auto podcast import Developer Profile

systemsrtk

3 plugins · 150 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Auto podcast import

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-podcast-import/assets/css/admin.css/wp-content/plugins/auto-podcast-import/assets/js/admin.js
Script Paths
/wp-content/plugins/auto-podcast-import/assets/js/admin.js
Version Parameters
auto-podcast-import/assets/css/admin.css?ver=auto-podcast-import/assets/js/admin.js?ver=

HTML / DOM Fingerprints

JS Globals
AUPI_SLUG
FAQ

Frequently Asked Questions about Auto podcast import