
Feed Delay Security & Risk Analysis
wordpress.org/plugins/feed-delayStops a post from from immediately being published on feed.
Is Feed Delay Safe to Use in 2026?
Generally Safe
Score 85/100Feed Delay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "feed-delay" plugin v0.5 exhibits a strong security posture based on the static analysis provided. A significant strength is the complete absence of dangerous functions and SQL queries that do not utilize prepared statements. The presence of a nonce check is also a positive indicator of security awareness in its development. However, concerns arise from the 50% of output escaping, indicating that half of the plugin's outputs are not properly sanitized, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved. Additionally, the taint analysis revealed one flow with an unsanitized path, which, while not classified as critical or high severity in this analysis, warrants careful review as it represents a potential pathway for malicious input to be processed without adequate validation. The plugin's vulnerability history is clean, with no recorded CVEs, which is highly positive and suggests a history of secure development practices. Overall, while the foundation is solid with no exploitable vulnerabilities detected in the static analysis or history, the unescaped outputs and unsanitized taint flow represent areas for immediate improvement to further harden the plugin's security.
Key Concerns
- Half of outputs are not properly escaped
- Taint analysis shows unsanitized path
Feed Delay Security Vulnerabilities
Feed Delay Code Analysis
Output Escaping
Data Flow Analysis
Feed Delay Attack Surface
WordPress Hooks 4
Maintenance & Trust
Feed Delay Maintenance & Trust
Maintenance Signals
Community Trust
Feed Delay Alternatives
Decent Comments
decent-comments
Decent Comments shows what people say. A more engaging way to show comments.
Disable Feeds and Comments
disable-rss-feeds-and-comments
This WordPress plugin, "Disable RSS Feeds and Comments," gives you the ability to turn off both the RSS feeds and comments on pages and/or p …
mypace Remove Comments Feed Link
mypace-remove-comments-feed-link
This plugin will remove comments feed links from header, output only posts feed.
Remove Feed Links
remove-feed-links
Remove Feed Links is a simple plugin for removing feed links from the head of your web site.
Avatars for Comment Feeds
avatars-for-comment-feeds
This plugin will add avatars of comment-authors to the comment-feeds of your WordPress-Blog.
Feed Delay Developer Profile
6 plugins · 90 total installs
How We Detect Feed Delay
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
feed_delay_disable_feedfeed_delay_noncefd_no