Custom RSS Feeds by Envintus, LLC Security & Risk Analysis

wordpress.org/plugins/custom-feeds

Add custom RSS feeds to your WordPress installation and customize the feeds using theme templates.

20 active installs v1.0 PHP + WP 3.1+ Updated Aug 14, 2014
atomfeedsrss
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom RSS Feeds by Envintus, LLC Safe to Use in 2026?

Generally Safe

Score 85/100

Custom RSS Feeds by Envintus, LLC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'custom-feeds' plugin v1.0 appears to have a strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate good security practices, with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. There are also no file operations, external HTTP requests, or indicated issues with nonce or capability checks.

The vulnerability history is also clean, with zero known CVEs. This lack of historical vulnerabilities, coupled with the strong static analysis, suggests a well-developed and secure plugin. However, the complete absence of any entry points or taint flows is unusual and could indicate that the plugin's functionality might be very limited or primarily server-side with no direct user interaction points exposed through typical WordPress mechanisms. While this absence of entry points is a security strength, it also means the static analysis might not have had much to examine for potential vulnerabilities within active code execution paths.

In conclusion, based solely on the provided data, 'custom-feeds' v1.0 demonstrates excellent security practices and a clean vulnerability history. The primary concern is the extremely limited identified attack surface and taint analysis, which might suggest a lack of complex functionality or incomplete analysis coverage, rather than an inherent weakness. The plugin is, therefore, assessed as highly secure in its current state.

Vulnerabilities
None known

Custom RSS Feeds by Envintus, LLC Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom RSS Feeds by Envintus, LLC Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Custom RSS Feeds by Envintus, LLC Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menucustom-feeds.php:35
Maintenance & Trust

Custom RSS Feeds by Envintus, LLC Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedAug 14, 2014
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Custom RSS Feeds by Envintus, LLC Developer Profile

Hunter Satterwhite

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom RSS Feeds by Envintus, LLC

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-feeds/css/custom-feeds.css/wp-content/plugins/custom-feeds/js/custom-feeds.js
Script Paths
/wp-content/plugins/custom-feeds/js/custom-feeds.js
Version Parameters
custom-feeds/css/custom-feeds.css?ver=custom-feeds/js/custom-feeds.js?ver=

HTML / DOM Fingerprints

CSS Classes
custom-feeds-options
FAQ

Frequently Asked Questions about Custom RSS Feeds by Envintus, LLC