Feed Changer & Remover Security & Risk Analysis

wordpress.org/plugins/feed-changer

Feed Changer

100 active installs v0.3 PHP 7.0+ WP 3.0+ Updated May 19, 2024
feedfeed-changerrssrss-changerrss-protector
92
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 15, 2023
Safety Verdict

Is Feed Changer & Remover Safe to Use in 2026?

Generally Safe

Score 92/100

Feed Changer & Remover has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Feb 15, 2023Updated 1yr ago
Risk Assessment

The 'feed-changer' plugin v0.3 exhibits a mixed security posture. On the positive side, the static analysis reveals no identifiable direct attack surface through common entry points like AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all detected SQL queries utilize prepared statements, and there are no indications of dangerous function usage, file operations, or external HTTP requests, which are generally good security practices.

However, a significant concern arises from the output escaping. With only 53% of outputs properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks on all identified entry points (even if there are none listed, the lack of checks implies potential for future issues if entry points are added) is another weakness, as it leaves the plugin vulnerable to unauthorized actions if any vulnerabilities are discovered. The plugin's vulnerability history, including a past medium-severity XSS vulnerability, reinforces the concern regarding output sanitization, suggesting a pattern of incomplete input validation or output escaping.

In conclusion, while the plugin avoids common pitfalls like raw SQL and a large exposed attack surface, the inadequate output escaping and lack of comprehensive authorization checks present tangible risks. The past XSS vulnerability highlights a recurring issue that needs immediate attention to prevent future exploitation.

Key Concerns

  • Output escaping below 70%
  • No nonce checks on entry points
  • No capability checks on entry points
  • 1 medium severity vulnerability in history
Vulnerabilities
1 published

Feed Changer & Remover Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-25795medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Feed Changer <= 0.2 - Authenticated (Admin+) Stored Cross-Site Scripting

Feb 15, 2023 Patched in 0.3 (342d)
Version History

Feed Changer & Remover Release Timeline

v0.3Current
v0.21 CVE
v0.11 CVE
Code Analysis
Analyzed Mar 16, 2026

Feed Changer & Remover Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
19 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

53% escaped36 total outputs
Attack Surface

Feed Changer & Remover Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitindex.php:36
actionplugins_loadedindex.php:48
actiondo_feedindex.php:88
actiondo_feed_rdfindex.php:89
actiondo_feed_rssindex.php:90
actiondo_feed_rss2index.php:91
actiondo_feed_atomindex.php:92
actiondo_feed_rss2_commentsindex.php:93
actiondo_feed_atom_commentsindex.php:94
actionadmin_menusimple-class-options.php:23
Maintenance & Trust

Feed Changer & Remover Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 19, 2024
PHP min version7.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Feed Changer & Remover Developer Profile

Omid Shamloo

7 plugins · 8K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
158 days
View full developer profile
Detection Fingerprints

How We Detect Feed Changer & Remover

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Feed Changer & Remover