
Feed JSON Security & Risk Analysis
wordpress.org/plugins/feed-jsonAdds a new type of feed you can subscribe to.
Is Feed JSON Safe to Use in 2026?
Generally Safe
Score 85/100Feed JSON has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'feed-json' plugin v1.0.10 demonstrates a strong security posture based on the provided static analysis. The absence of any identifiable attack surface points, dangerous functions, raw SQL queries, file operations, external HTTP requests, or known vulnerabilities in its history is highly commendable. This suggests the developers have prioritized secure coding practices and have maintained a clean track record.
However, there are a few areas that warrant attention. The low percentage of properly escaped outputs (33%) indicates a potential risk of cross-site scripting (XSS) vulnerabilities if the unescaped outputs are rendered in a user's browser. While the static analysis did not identify specific taint flows or vulnerabilities, this output escaping issue remains a significant concern. Additionally, the complete lack of nonce and capability checks, while not directly leading to identified issues in this scan, could be a concern in larger or more complex plugins where such checks are crucial for preventing CSRF and unauthorized actions.
In conclusion, the plugin is in a generally good security state due to its limited attack surface and lack of known vulnerabilities. The primary weakness lies in output escaping, which should be addressed to mitigate potential XSS risks. The absence of critical or high severity issues in the taint analysis and vulnerability history are positive indicators. Addressing the output escaping would significantly enhance its overall security.
Key Concerns
- Low percentage of properly escaped outputs
- Lack of nonce checks
- Lack of capability checks
Feed JSON Security Vulnerabilities
Feed JSON Code Analysis
Output Escaping
Feed JSON Attack Surface
WordPress Hooks 4
Maintenance & Trust
Feed JSON Maintenance & Trust
Maintenance Signals
Community Trust
Feed JSON Alternatives
Feed JSON
tabletize-json-connector
Expose Wordpress posts to be used by a Tabletize data source.
JSON Feed (jsonfeed.org)
jsonfeed
Adds feeds in JSON Feed format.
JSON feed
json-feed
Pretty simple, really. Adds a new type of feed you can subscribe to. Simply
JSON Feeder
json-feeder
Adds a feed based on the jsonfeed.org standard that one can subscribe to or parse.
WP API JSON READER
wp-api-json-reader
Get and show posts from an other WP website which have installed the WP REST API and provide json feeds via the API
Feed JSON Developer Profile
7 plugins · 12K total installs
How We Detect Feed JSON
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feed-json/template/feed-json.php