
Blogroll Widget with RSS Feeds Security & Risk Analysis
wordpress.org/plugins/blogroll-rss-widgetDisplays the recent posts of your blogroll links via RSS Feeds in a customizable sidebar widget
Is Blogroll Widget with RSS Feeds Safe to Use in 2026?
Generally Safe
Score 85/100Blogroll Widget with RSS Feeds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The blogroll-rss-widget v2.2 plugin exhibits a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) associated with this plugin, and the code analysis shows that all SQL queries utilize prepared statements, which is a strong defense against SQL injection. Additionally, the absence of external HTTP requests, shortcodes, cron events, and REST API routes suggests a limited attack surface. However, several significant concerns are present. The static analysis reveals the use of the deprecated and insecure `create_function` function, which can be a vector for code injection if not handled with extreme care. Furthermore, a critically low percentage (4%) of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce checks and capability checks on any potential entry points, coupled with the presence of the `create_function` function, creates a dangerous combination. While the plugin currently has no known CVEs and a seemingly small attack surface, the identified code quality issues and lack of fundamental security checks leave it vulnerable to exploitation.
Key Concerns
- Dangerous function 'create_function' used
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
Blogroll Widget with RSS Feeds Security Vulnerabilities
Blogroll Widget with RSS Feeds Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Blogroll Widget with RSS Feeds Attack Surface
WordPress Hooks 2
Maintenance & Trust
Blogroll Widget with RSS Feeds Maintenance & Trust
Maintenance Signals
Community Trust
Blogroll Widget with RSS Feeds Alternatives
Blogroll Links
blogroll-links
Display your blogroll links anywhere in posts or pages using a simple shortcode.
Bookmarks Shortcode
bookmarks-shortcode
Creates shortcodes that will generate an unordered list of your WordPress links (bookmarks).
Display Links by Category
display-links-by-category
A simple shortcode plugin for displaying links by category through custom fields.
FAVIROLL – FAVIcons for blogROLL
faviroll
This plugin convert the favicon.ico from the blogroll sites into PNG images and save this in a local cache file. The conversion process works just on …
Blogroll Links Favicons
blogroll-links-favicons
Automatically adds favicons to blogroll/bookmark links.
Blogroll Widget with RSS Feeds Developer Profile
3 plugins · 1K total installs
How We Detect Blogroll Widget with RSS Feeds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blogroll-rss-widget/blogroll-rss-widget.css/wp-content/plugins/blogroll-rss-widget/blogroll-rss-widget.jsblogroll-rss-widget/blogroll-rss-widget.css?ver=blogroll-rss-widget/blogroll-rss-widget.js?ver=HTML / DOM Fingerprints
blogroll_widget_rss