
Feed Subscriber Stats Security & Risk Analysis
wordpress.org/plugins/feed-subscriber-statsEver wanted to see your FeedBurner stats on the Wordpress Dashboard? Well now you can with this simple plugin. The plugin uses FeedBurner's Aware …
Is Feed Subscriber Stats Safe to Use in 2026?
Generally Safe
Score 85/100Feed Subscriber Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "feed-subscriber-stats" v3.0.6 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates excellent practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerability history (CVEs). The attack surface appears minimal, with no apparent AJAX handlers, REST API routes, shortcodes, or cron events that would typically represent entry points for attackers. Furthermore, the absence of external HTTP requests and file operations reduces potential exposure vectors.
However, significant concerns arise from the output escaping. With 14 total outputs and 0% properly escaped, this represents a critical weakness. Unescaped output is a common gateway for Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the WordPress dashboard or user-facing pages. The taint analysis, while showing no critical or high severity flows, does indicate 4 flows with unsanitized paths, which, when combined with the lack of output escaping, could still lead to exploitable situations. The complete absence of nonce and capability checks on all identified entry points (though the entry point count is zero) is also a noteworthy omission that could be leveraged if new entry points are introduced in future versions.
In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL handling, the severe lack of output escaping poses a substantial XSS risk. The absence of broader security checks like nonces and capability checks on the limited identified components further contributes to potential vulnerabilities. The developer should prioritize addressing the output escaping issues immediately.
Key Concerns
- 0% output escaping
- 4 flows with unsanitized paths
- 0 capability checks on entry points
- 0 nonce checks on entry points
Feed Subscriber Stats Security Vulnerabilities
Feed Subscriber Stats Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Feed Subscriber Stats Attack Surface
WordPress Hooks 5
Maintenance & Trust
Feed Subscriber Stats Maintenance & Trust
Maintenance Signals
Community Trust
Feed Subscriber Stats Alternatives
RSS Redirect & Feedburner Alternative
feedburner-alternative-and-rss-redirect
Free Feedburner Alternative and RSS Redirect plugin from follow.it.
GloDer RSS
gloder-rss
A plugin to add a sidebar widget for RSS feeds of the current site.
Disable Feeds
disable-feeds
Disables all RSS/Atom/RDF feeds on your WordPress site.
GN Publisher: Google News Compatible RSS Feeds
gn-publisher
GN Publisher makes RSS feeds that comply with the Google News RSS Feed Technical Requirements for including your site in the Google News.
Disable Feeds WP
disable-feeds-wp
Disables all RSS/Atom/RDF feeds on your WordPress site.
Feed Subscriber Stats Developer Profile
4 plugins · 830 total installs
How We Detect Feed Subscriber Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feed-subscriber-stats/images/rss.jpgHTML / DOM Fingerprints
circulationjQuery