
Feed Changer & Remover Security & Risk Analysis
wordpress.org/plugins/feed-changerFeed Changer
Is Feed Changer & Remover Safe to Use in 2026?
Generally Safe
Score 92/100Feed Changer & Remover has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'feed-changer' plugin v0.3 exhibits a mixed security posture. On the positive side, the static analysis reveals no identifiable direct attack surface through common entry points like AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all detected SQL queries utilize prepared statements, and there are no indications of dangerous function usage, file operations, or external HTTP requests, which are generally good security practices.
However, a significant concern arises from the output escaping. With only 53% of outputs properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks on all identified entry points (even if there are none listed, the lack of checks implies potential for future issues if entry points are added) is another weakness, as it leaves the plugin vulnerable to unauthorized actions if any vulnerabilities are discovered. The plugin's vulnerability history, including a past medium-severity XSS vulnerability, reinforces the concern regarding output sanitization, suggesting a pattern of incomplete input validation or output escaping.
In conclusion, while the plugin avoids common pitfalls like raw SQL and a large exposed attack surface, the inadequate output escaping and lack of comprehensive authorization checks present tangible risks. The past XSS vulnerability highlights a recurring issue that needs immediate attention to prevent future exploitation.
Key Concerns
- Output escaping below 70%
- No nonce checks on entry points
- No capability checks on entry points
- 1 medium severity vulnerability in history
Feed Changer & Remover Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Feed Changer <= 0.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Feed Changer & Remover Release Timeline
Feed Changer & Remover Code Analysis
Output Escaping
Feed Changer & Remover Attack Surface
WordPress Hooks 10
Maintenance & Trust
Feed Changer & Remover Maintenance & Trust
Maintenance Signals
Community Trust
Feed Changer & Remover Alternatives
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging
wp-rss-aggregator
The #1 WordPress RSS aggregator to quickly import RSS feeds, build a news aggregator, and for easy autoblogging.
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator
feedzy-rss-feeds
The most powerful WordPress RSS aggregator, helping you curate content, autoblog, import RSS & display unlimited RSS feeds within a few minutes.
PowerPress Podcasting plugin by Blubrry
powerpress
No. 1 Podcasting plugin for WordPress.
Disable Feeds
disable-feeds
Disables all RSS/Atom/RDF feeds on your WordPress site.
GN Publisher: Google News Compatible RSS Feeds
gn-publisher
GN Publisher makes RSS feeds that comply with the Google News RSS Feed Technical Requirements for including your site in the Google News.
Feed Changer & Remover Developer Profile
7 plugins · 8K total installs
How We Detect Feed Changer & Remover
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.