
Content Fetcher Security & Risk Analysis
wordpress.org/plugins/content-fetcherFetch content from any website with simple shortcode
Is Content Fetcher Safe to Use in 2026?
Mostly Safe
Score 78/100Content Fetcher is generally safe to use. 1 past CVE were resolved. Keep it updated.
The 'content-fetcher' plugin version 1.1 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for its SQL queries and has no external HTTP requests or bundled libraries, which are common sources of vulnerabilities. The attack surface is also relatively small with only one shortcode entry point, and importantly, all identified entry points appear to lack authentication checks. However, several significant concerns exist. The most pressing is the presence of one unpatched medium severity vulnerability, historically related to Cross-Site Scripting (XSS), which represents a direct and present danger to users if exploited. Furthermore, the static analysis reveals a critical flaw in output escaping, with 100% of outputs being improperly escaped, making it highly susceptible to XSS attacks across all its outputs. The lack of nonce and capability checks on its single shortcode entry point, despite the absence of AJAX or REST API routes, means any user can trigger its functionality and potentially exploit the unescaped output. The taint analysis showing zero flows is a positive sign, but it doesn't mitigate the clear output escaping and historical XSS vulnerabilities. In conclusion, while the plugin avoids some common pitfalls, the unpatched XSS vulnerability combined with pervasive output escaping issues and a lack of proper authorization on its shortcode presents a significant risk.
Key Concerns
- Unpatched medium severity CVE (XSS)
- 100% of outputs unescaped
- Missing nonce checks on entry points
- Missing capability checks on entry points
Content Fetcher Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Content Fetcher <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Content Fetcher Code Analysis
SQL Query Safety
Output Escaping
Content Fetcher Attack Surface
Shortcodes 1
Maintenance & Trust
Content Fetcher Maintenance & Trust
Maintenance Signals
Community Trust
Content Fetcher Alternatives
WP Scraper
wp-scraper
This Wordpress Scraper allows you to move a non-Wordpress website into a Wordpress site.
RSSInjection
rss-injection
Inject content into your RSS feed to entice people to subscribe or allow you to add a message so if the feed it aggregated onto another site it is at …
Kickscraper
kickscraper
Kick Scraper is a lightweight plugin for managing your Kickscraper application.
Cherry Picker
cherry-picker
Cherry Picker is a versatile content grabber designed to effortlessly copy content from any eCommerce website and integrate it directly into your WooC …
News-Parser
news-parser
News-parser WordPress Plugin
Content Fetcher Developer Profile
2 plugins · 200 total installs
How We Detect Content Fetcher
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/content-fetcher/dom.php