Disable RSS Security & Risk Analysis

wordpress.org/plugins/disable-rss

Disables all RSS feeds.

500 active installs v1.0 PHP + WP 2.5.1+ Updated Dec 4, 2008
disablerss
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Disable RSS Safe to Use in 2026?

Generally Safe

Score 85/100

Disable RSS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 17yr ago
Risk Assessment

The "disable-rss" plugin v1.0 presents a surprisingly clean static analysis report, indicating a potentially robust security posture. The absence of any identified dangerous functions, direct SQL queries, unescaped output, file operations, or external HTTP requests is commendable. Furthermore, the lack of any documented vulnerability history, including CVEs of any severity, suggests a history of responsible development. The plugin appears to have a very small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, which further limits potential exploitation vectors. There are no taint analysis findings, indicating that any potential data flows are handled securely.

However, the most significant concern arises from the complete absence of nonce checks and capability checks. While the attack surface is currently zero, this lack of fundamental WordPress security mechanisms means that if any functionality were to be added in the future without proper authorization checks, it could be exploited. This is a critical omission for any plugin that interacts with the WordPress environment, even if currently benign. The plugin's strengths lie in its adherence to secure coding practices for the limited functionality it offers, but the missing authorization checks are a substantial weakness that could become a problem if the plugin evolves.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Disable RSS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Disable RSS Release Timeline

v1.0Current
Code Analysis
Analyzed Mar 16, 2026

Disable RSS Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Disable RSS Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actiondo_feeddisable-rss.php:11
actiondo_feed_rdfdisable-rss.php:12
actiondo_feed_rssdisable-rss.php:13
actiondo_feed_rss2disable-rss.php:14
actiondo_feed_atomdisable-rss.php:15
Maintenance & Trust

Disable RSS Maintenance & Trust

Maintenance Signals

WordPress version tested2.7
Last updatedDec 4, 2008
PHP min version
Downloads21K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

Disable RSS Developer Profile

Clifton Griffin

6 plugins · 3K total installs

90
trust score
Avg Security Score
85/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Disable RSS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Disable RSS