
Cartograf Featured-image in Feed Security & Risk Analysis
wordpress.org/plugins/cartograf-featured-image-in-feedIncludes the featured image of a post at the beginning of the item's content in the WordPress generated feeds. With this plugin, you no longer ne …
Is Cartograf Featured-image in Feed Safe to Use in 2026?
Generally Safe
Score 85/100Cartograf Featured-image in Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of 'cartograf-featured-image-in-feed' v1.2.1 indicates a generally good security posture with no identified vulnerabilities in the tested areas. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a positive sign. Furthermore, the lack of known CVEs and a clean vulnerability history suggest the plugin has been developed with security in mind or has not yet attracted significant attention from attackers.
However, a critical weakness is the complete absence of output escaping for the single identified output. This creates a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users, if not properly sanitized before rendering, could be exploited by an attacker to inject malicious scripts. The lack of capability checks, nonce checks, and authentication for any potential (though currently zero) entry points also represents a missed opportunity to further harden the plugin's security. While the current attack surface is zero, this might change in future versions, and these checks would be essential to maintain security.
In conclusion, while the plugin's foundational code appears robust and free from common vulnerabilities like SQL injection or arbitrary file operations, the unescaped output is a glaring security flaw that must be addressed immediately. The vulnerability history is positive, but this should not lead to complacency, especially given the identified output sanitization issue.
Key Concerns
- Unescaped output detected
Cartograf Featured-image in Feed Security Vulnerabilities
Cartograf Featured-image in Feed Code Analysis
Output Escaping
Cartograf Featured-image in Feed Attack Surface
WordPress Hooks 4
Maintenance & Trust
Cartograf Featured-image in Feed Maintenance & Trust
Maintenance Signals
Community Trust
Cartograf Featured-image in Feed Alternatives
RSS Chimp – Add Featured Images to WP RSS Feeds (Mailchimp, Google News, Feedly)
rss-chimp
Add featured images to RSS feeds for Mailchimp, Google News, Feedly and email newsletters. Enhance WordPress RSS feed with thumbnails for better email …
Add Featured Image to RSS Feed
add-featured-image-to-rss-feed
Adds the featured image attached to posts to the beginning of the post content and excerpt in RSS feeds.
Featured Image in RSS Feed by MailerLite
mailerlite-featured-image-in-rss-feed
This plugin automatically adds featured images of your posts into the RSS feed.
Feed Post Thumbnail
wp-feed-post-thumbnail
Adds MRSS namespace to the feed and uses post-thumbnail as media element in the feed. Settings available under Settings -> Reading.
Simple Statistics for Feeds
simple-feed-stats
Tracks your feeds and displays your feed count via shortcode.
Cartograf Featured-image in Feed Developer Profile
2 plugins · 230 total installs
How We Detect Cartograf Featured-image in Feed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<div style="display: block; margin-right: 10px; text-align:left;"><a title="See content in " href="