
Extra Feed Links Security & Risk Analysis
wordpress.org/plugins/extra-feed-linksAdds extra feed auto-discovery links to various page types (categories, tags, search results etc.)
Is Extra Feed Links Safe to Use in 2026?
Generally Safe
Score 85/100Extra Feed Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The extra-feed-links plugin, version 1.1.5.1, presents a generally positive security posture based on the static analysis. It demonstrates good practices by having no external HTTP requests, file operations, or raw SQL queries. The complete absence of SQL queries suggests it doesn't interact with the database directly, which is a significant strength. The presence of nonce and capability checks, while limited in number, indicates an awareness of WordPress security mechanisms.
However, a critical concern arises from the output escaping. With 12 total outputs and 0% properly escaped, this plugin is highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data or data processed by the plugin that is later displayed on the frontend or backend is at risk of being injected with malicious scripts. While the attack surface is currently zero and there are no known vulnerabilities, this lack of output sanitization is a severe oversight that could be easily exploited.
The vulnerability history is clean, with no recorded CVEs. This, combined with the minimal attack surface, suggests that in the past, the plugin may have been developed with security in mind or has not yet been a target for exploitation. However, the current static analysis highlights a significant, exploitable flaw that is not reflected in past vulnerability data. The plugin's strengths in other areas are overshadowed by this critical output escaping deficiency.
Key Concerns
- All output not properly escaped
- Limited nonce and capability checks
Extra Feed Links Security Vulnerabilities
Extra Feed Links Code Analysis
Output Escaping
Extra Feed Links Attack Surface
WordPress Hooks 2
Maintenance & Trust
Extra Feed Links Maintenance & Trust
Maintenance Signals
Community Trust
Extra Feed Links Alternatives
Disable Feeds and Comments
disable-rss-feeds-and-comments
This WordPress plugin, "Disable RSS Feeds and Comments," gives you the ability to turn off both the RSS feeds and comments on pages and/or p …
mypace Remove Comments Feed Link
mypace-remove-comments-feed-link
This plugin will remove comments feed links from header, output only posts feed.
Feedme
feedme
Feedme is a simple and powerful tool that will surely enhance any WordPress install. As feed readers become more advanced and are capable of handling …
Separate Feed Comments and Trackbacks
separate-feed-comments-and-trackbacks
Remove trackbacks from your sitewide and individual post comment feeds, and/or have alternate feeds for comments or trackbacks only.
Sexy RSS Footer
sexy-rss-footer
Sexy RSS Footer enables you to add any possible content at the end of every feed entry. This includes variables like number of comments, author etc.
Extra Feed Links Developer Profile
20 plugins · 28K total installs
How We Detect Extra Feed Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/extra-feed-links/inc/scbOptions.phpHTML / DOM Fingerprints
<!-- Generated by Extra Feed Links -->