
feedgator Security & Risk Analysis
wordpress.org/plugins/feedaggregatorFeed(Aggre)gator merges a group of RSS feeds into a single widgetized list.
Is feedgator Safe to Use in 2026?
Generally Safe
Score 85/100feedgator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "feedaggregator" plugin v1.0.2 exhibits a strong security posture based on the provided static analysis. Notably, there are no identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) that are unprotected. The plugin also demonstrates good practices in its handling of SQL queries, with 100% utilizing prepared statements, and avoids dangerous functions and file operations. The lack of identified critical or high-severity taint flows further suggests a well-developed codebase from a security perspective.
However, a significant concern arises from the output escaping analysis, where 0% of the 12 total outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, as unsanitized user-supplied data could be directly rendered in the browser. The absence of nonces on any potential entry points, though the attack surface is currently zero, is a missed opportunity for defense-in-depth should new entry points be added in the future. The vulnerability history is clean, with no recorded CVEs, which is a positive indicator, but it doesn't negate the risks identified in the code analysis.
In conclusion, while the plugin demonstrates excellent preventative measures against common attack vectors and has a clean vulnerability history, the significant lack of output escaping is a critical weakness that exposes it to XSS risks. Addressing this output sanitization issue should be the immediate priority for improving its security.
Key Concerns
- Output escaping is not performed
- No nonce checks on any entry points
feedgator Security Vulnerabilities
feedgator Release Timeline
feedgator Code Analysis
Output Escaping
feedgator Attack Surface
WordPress Hooks 1
Maintenance & Trust
feedgator Maintenance & Trust
Maintenance Signals
Community Trust
feedgator Alternatives
Disable Feeds
disable-feeds
Disables all RSS/Atom/RDF feeds on your WordPress site.
Disable Feeds WP
disable-feeds-wp
Disables all RSS/Atom/RDF feeds on your WordPress site.
FeedWordPress
feedwordpress
FeedWordPress syndicates content from feeds you choose into your WordPress weblog.
RSS Just Better
rss-just-better
Displays a list of RSS/Atom feed items given the feed URL and other parameters (optionals). Highly customizable.
Feed Template Customize
feed-template-customize
This plugin modifies RSS feeds and ATOM feeds as you want.
feedgator Developer Profile
1 plugin · 20 total installs
How We Detect feedgator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feedaggregator/feedgator.php/wp-content/plugins/feedaggregator/feedgator.css/wp-content/plugins/feedaggregator/feedgator.js/wp-content/plugins/feedaggregator/feedgator.jsfeedaggregator/feedgator.css?ver=feedaggregator/feedgator.js?ver=HTML / DOM Fingerprints
feedgator-excerptfeedgator-authorfeedgator-titlefeedgator-date<!-- To make custom names appear for entries from certain authors, --><!-- create a pair of strings with the author's handle and the name --><!-- you want to appear. --><!-- EXAMPLES: -->+29 morefeedgator_numitemsfeedgator_widgettitlefeedgator_rss_feedsfeedgator_no_title_textfeedgator_display_methodfeedgator_display_excerpt+5 morefeedgator_item_author_arrfeedgator_item_class_arr