
Feed Plus Security & Risk Analysis
wordpress.org/plugins/feedplusMit Feed Plus ist man in der Lage Werbung, Infos und andere wichtige Dinge direkt im Feed, und zwar nach einem Beitrag oder danach, zu publizieren.
Is Feed Plus Safe to Use in 2026?
Generally Safe
Score 85/100Feed Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "feedplus" v3.1 plugin exhibits a mixed security posture. On the one hand, the static analysis shows no known dangerous functions, no direct SQL queries (all use prepared statements), no file operations, and no external HTTP requests. Furthermore, there's a complete absence of publicly disclosed vulnerabilities, which is a positive indicator. However, significant concerns arise from the output escaping results. With 100% of analyzed outputs unescaped, this presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities, especially if any of the analyzed flows involve user-provided data being displayed directly in the frontend without proper sanitization. The taint analysis also highlights "flows with unsanitized paths," which, while not classified as critical or high severity by the tool, warrants further investigation as it points to potential weaknesses in how data is handled. The lack of documented capabilities checks or nonce checks across its limited entry points (which are currently zero) is not a direct risk in this version due to the absence of those entry points, but it indicates a potential gap in security practices should new entry points be added in future updates without corresponding security checks. Overall, while the plugin benefits from a clean vulnerability history and a lack of high-risk code patterns, the unescaped output and identified unsanitized paths are significant weaknesses that need to be addressed.
Key Concerns
- Unescaped output across all analyzed outputs
- Flows with unsanitized paths identified
Feed Plus Security Vulnerabilities
Feed Plus Release Timeline
Feed Plus Code Analysis
Output Escaping
Data Flow Analysis
Feed Plus Attack Surface
WordPress Hooks 2
Maintenance & Trust
Feed Plus Maintenance & Trust
Maintenance Signals
Community Trust
Feed Plus Alternatives
LH RSS Shortcode
lh-rss-shortcode
A simple plugin to display RSS feeds in posts and pages using a shortcode.
WP RSS Fetcher ShortCode
wp-rss-fetcher-shortcode
Easily fetches RSS feeds from external sources and embed them into posts or pages with a shortcode.
Mo RSS Feed
mo-rss-feed
Display an RSS Feed with images in WordPress using a shortcode.
RSS Responsive Caption
rss-responsive-caption
Improves WordPress caption elements so captioned images in RSS feeds responsively adjust to fit within Google Reader’s screen on Android devices.
WP Kill In Feed
wp-kill-in-feed
Super-simple shortcodes to control what's in your RSS feed.
Feed Plus Developer Profile
13 plugins · 5K total installs
How We Detect Feed Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.