
Disable Feeds Security & Risk Analysis
wordpress.org/plugins/disable-feedsDisables all RSS/Atom/RDF feeds on your WordPress site.
Is Disable Feeds Safe to Use in 2026?
Generally Safe
Score 85/100Disable Feeds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'disable-feeds' plugin v1.4.4 exhibits a generally good security posture based on the static analysis provided. The absence of dangerous functions, SQL queries not using prepared statements, file operations, and external HTTP requests is a significant strength. Furthermore, the plugin has no known vulnerabilities, indicating a history of stability and potentially good security practices from the developer.
However, there are notable areas of concern. The analysis reveals that 100% of the observed outputs are not properly escaped. This is a critical security weakness that could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sanitization. Additionally, the taint analysis identified two flows with unsanitized paths, which, while not rated as critical or high severity in this specific scan, warrants attention as it suggests potential pathways for malicious input to affect program execution.
In conclusion, while the plugin's core functionality appears to be implemented securely, the lack of output escaping presents a significant risk. The unsanitized paths, though not explicitly severe, also suggest potential improvements. Addressing the output escaping issue should be a priority to mitigate XSS risks. The clean vulnerability history is positive, but it should not lead to complacency, especially given the identified code concerns.
Key Concerns
- 100% of outputs unescaped
- 2 flows with unsanitized paths
Disable Feeds Security Vulnerabilities
Disable Feeds Code Analysis
Output Escaping
Data Flow Analysis
Disable Feeds Attack Surface
WordPress Hooks 5
Maintenance & Trust
Disable Feeds Maintenance & Trust
Maintenance Signals
Community Trust
Disable Feeds Alternatives
Disable RSS, RDF, and Atom Feeds
disable-rss-rdf-atom-feeds
Disable all RSS, RDF, and Atom feeds on your WordPress site with the option to control behavior such as redirection or issuing a 404 error.
Disable Feeds WP
disable-feeds-wp
Disables all RSS/Atom/RDF feeds on your WordPress site.
Disable Feeds and Comments
disable-rss-feeds-and-comments
This WordPress plugin, "Disable RSS Feeds and Comments," gives you the ability to turn off both the RSS feeds and comments on pages and/or p …
RSS Just Better
rss-just-better
Displays a list of RSS/Atom feed items given the feed URL and other parameters (optionals). Highly customizable.
Disable Feeds And Hide Usernames
disable-feeds-and-hide-usernames
This tiny and lightweight plugin removes all the rss feeds and hides usernames.
Disable Feeds Developer Profile
46 plugins · 4.0M total installs
How We Detect Disable Feeds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
disable_feeds_redirect_yesdisable_feeds_redirect_nodisable_feeds_allow_main