
FeedWordPress Security & Risk Analysis
wordpress.org/plugins/feedwordpressFeedWordPress syndicates content from feeds you choose into your WordPress weblog.
Is FeedWordPress Safe to Use in 2026?
Generally Safe
Score 97/100FeedWordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The security posture of FeedWordPress v2025.1211 presents a mixed bag of strengths and significant concerns. While the plugin demonstrates good practices in output escaping (97%) and a strong utilization of prepared statements for SQL queries (47% is decent, though could be higher), the presence of 8 dangerous function calls, notably `unserialize`, warrants close attention. The attack surface is relatively small with 3 entry points, but critically, all 3 of these are unprotected AJAX handlers, posing a substantial risk for unauthorized actions. The taint analysis showing no critical or high severity flows is a positive sign, suggesting that direct code execution or data compromise through untrusted input might be less prevalent than other potential risks.
The plugin's vulnerability history, with 5 known CVEs including one critical, is a major red flag. The recurring themes of Authorization Bypass, SQL Injection, and Cross-site Scripting indicate persistent weaknesses in input validation and access control. The fact that the last vulnerability was in March 2024, and there are currently no unpatched CVEs, suggests that recent updates have addressed past issues, but the historical pattern raises concerns about the overall robustness of its security. The presence of critical vulnerabilities in its past, even if currently patched, points to a codebase that has historically been susceptible to severe exploits.
In conclusion, FeedWordPress v2025.1211 has made strides in areas like output sanitization and SQL query preparation. However, the unprotected AJAX handlers and the history of critical vulnerabilities, particularly those related to authorization and injection, represent significant security weaknesses that require careful management. The presence of `unserialize` without explicit context on its usage also introduces a potential attack vector that should be carefully reviewed.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function: unserialize
- Historical critical CVE
- 1 critical CVE in history
- Authorization Bypass CVEs
- SQL Injection CVEs
- XSS CVEs
FeedWordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
FeedWordPress <= 2022.0222 - Insecure Direct Object Referece
FeedWordPress <= 2021.0713 - Reflected Cross-Site Scripting
FeedWordPress < 2015.0514 - SQL Injection
FeedWordPress < 2015.0514 - Reflected Cross-Site Scripting
FeedWordPress < 2015.0426 - Cross-Site Scripting
FeedWordPress Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
FeedWordPress Attack Surface
AJAX Handlers 3
WordPress Hooks 68
Scheduled Events 1
Maintenance & Trust
FeedWordPress Maintenance & Trust
Maintenance Signals
Community Trust
FeedWordPress Alternatives
FeedWordPress Advanced Filters
faf
Author: Bas Schuiling
YD BuddyPress Feed Syndication
yd-buddypress-feed-syndication
Syndicate RSS feeds into your user or group Activity stream
Disable Feeds
disable-feeds
Disables all RSS/Atom/RDF feeds on your WordPress site.
Disable Feeds WP
disable-feeds-wp
Disables all RSS/Atom/RDF feeds on your WordPress site.
RSS Just Better
rss-just-better
Displays a list of RSS/Atom feed items given the feed URL and other parameters (optionals). Highly customizable.
FeedWordPress Developer Profile
2 plugins · 10K total installs
How We Detect FeedWordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feedwordpress/css/feedwordpress.css/wp-content/plugins/feedwordpress/css/admin.css/wp-content/plugins/feedwordpress/css/inspect.css/wp-content/plugins/feedwordpress/js/feedwordpress.js/wp-content/plugins/feedwordpress/js/jquery.tablesorter.min.js/wp-content/plugins/feedwordpress/js/postmeta.jsfeedwordpress/css/feedwordpress.css?ver=feedwordpress/css/admin.css?ver=feedwordpress/css/inspect.css?ver=feedwordpress/js/feedwordpress.js?ver=feedwordpress/js/jquery.tablesorter.min.js?ver=feedwordpress/js/postmeta.js?ver=HTML / DOM Fingerprints
feedwordpressfeedwordpress-settingsfeedwordpress-adminfeedwordpress-diagnosticfeedwordpress-syndicationfeedwordpress-inspect-post-metafeedwordpress-link-settingsfeedwordpress-syndication-settings<!-- FeedWordPress Admin Page --><!-- FeedWordPress Diagnostic Page --><!-- FeedWordPress Syndication Page --><!-- FeedWordPress Post Meta Inspector -->+4 moredata-feedwordpress-iddata-feedwordpress-urldata-feedwordpress-post-idfeedwordpressFeedWordPressDebugFeedWordPressData