
FeedWordPress Advanced Filters Security & Risk Analysis
wordpress.org/plugins/fafAuthor: Bas Schuiling
Is FeedWordPress Advanced Filters Safe to Use in 2026?
Use With Caution
Score 63/100FeedWordPress Advanced Filters has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The faf plugin version 0.6.2 presents a concerning security posture, primarily due to its significant attack surface exposed without proper authentication. With two unprotected AJAX handlers, there's a direct avenue for unauthorized actions. The static analysis also reveals a critical flaw in the use of the `unserialize` function, which, without proper sanitization of its input, can lead to Remote Code Execution vulnerabilities. Furthermore, only a meager 6% of outputs are properly escaped, increasing the risk of Cross-Site Scripting (XSS) attacks. The vulnerability history, including a currently unpatched medium-severity CVE related to XSS, reinforces these concerns and suggests a pattern of security weaknesses in the plugin. While the use of prepared statements for SQL queries is a positive, it is overshadowed by the critical issues in authentication, input sanitization, and output escaping, making this plugin a high-risk component.
Key Concerns
- Unprotected AJAX handlers (2)
- Dangerous function: unserialize
- Low output escaping percentage (6%)
- Missing nonce checks
- Missing capability checks
- Currently unpatched CVE (medium)
FeedWordPress Advanced Filters Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
FeedWordPress Advanced Filters <= 0.6.2 - Reflected Cross-Site Scripting
FeedWordPress Advanced Filters Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
FeedWordPress Advanced Filters Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Maintenance & Trust
FeedWordPress Advanced Filters Maintenance & Trust
Maintenance Signals
Community Trust
FeedWordPress Advanced Filters Alternatives
FeedWordPress
feedwordpress
FeedWordPress syndicates content from feeds you choose into your WordPress weblog.
YD BuddyPress Feed Syndication
yd-buddypress-feed-syndication
Syndicate RSS feeds into your user or group Activity stream
Disable Feeds
disable-feeds
Disables all RSS/Atom/RDF feeds on your WordPress site.
Disable Feeds WP
disable-feeds-wp
Disables all RSS/Atom/RDF feeds on your WordPress site.
RSS Just Better
rss-just-better
Displays a list of RSS/Atom feed items given the feed URL and other parameters (optionals). Highly customizable.
FeedWordPress Advanced Filters Developer Profile
3 plugins · 320 total installs
How We Detect FeedWordPress Advanced Filters
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/faf/faf_style.css/wp-content/plugins/faf/faf.js/wp-content/plugins/faf/faf.jsfaf_stylefaf-jsHTML / DOM Fingerprints
fafFilterdata-faf-nonceajax_object/wp-json/faf/