
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Security & Risk Analysis
wordpress.org/plugins/feedzy-rss-feedsThe most powerful WordPress RSS aggregator, helping you curate content, autoblog, import RSS & display unlimited RSS feeds within a few minutes.
Is RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Safe to Use in 2026?
Generally Safe
Score 92/100RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator has a strong security track record. Known vulnerabilities have been patched promptly.
The Feedzy RSS Feeds plugin version 5.1.2 exhibits a mixed security posture. While it demonstrates good practices like a high percentage of prepared SQL statements and properly escaped output, several areas raise concerns. The significant attack surface, with 6 out of 11 entry points lacking authorization checks, is a primary risk. This includes 6 unprotected AJAX handlers, which are often exploited for privilege escalation or unauthorized actions if not properly secured. Taint analysis, although showing no critical or high severity flows, did reveal 3 flows with unsanitized paths, indicating potential for local file inclusion or other path manipulation vulnerabilities. The plugin's vulnerability history is particularly worrying, with 11 known CVEs, all of which are listed as currently patched. However, the past prevalence of critical and high severity vulnerabilities like SSRF, XSS, SQL Injection, and Missing Authorization suggests a pattern of security weaknesses that have required significant patching over time. The fact that all past vulnerabilities are patched is positive, but the sheer number and types of past issues, coupled with the current unprotected attack surface, warrants caution.
Key Concerns
- Large attack surface without auth checks
- Unsanitized paths in taint analysis
- High number of known CVEs in history
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Security Vulnerabilities
CVEs by Year
Severity Breakdown
11 total CVEs
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1.1 - Unauthenticated Blind Server-Side Request Forgery
Feedzy RSS Feeds Lite <= 5.1.0 - Authenticated (Subscriber+) Server-Side Request Forgery
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF)
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Error Message
RSS Aggregator by Feedzy <= 4.4.2 - Missing Authorization to Arbitrary Page Creation and Publication
RSS Aggregator by Feedzy <= 4.4.2 - Authenticated(Contributor+) SQL Injection
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.1 - Missing Authorization
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Authenticated (Author+) Stored Cross-Site Scripting
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Missing Authorization
RSS Aggregator by Feedzy <= 4.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
RSS Aggregator by Feedzy <= 3.4.2 - Cross-Site Request Forgery Bypass
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Attack Surface
AJAX Handlers 7
REST API Routes 3
Shortcodes 1
WordPress Hooks 146
Maintenance & Trust
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Maintenance & Trust
Maintenance Signals
Community Trust
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Alternatives
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging
wp-rss-aggregator
The #1 WordPress RSS aggregator to quickly import RSS feeds, build a news aggregator, and for easy autoblogging.
RSS Feed Retriever
wp-rss-retriever
The fastest RSS feeds plugin for WordPress. Includes excerpt & thumbnail image. Use as a news aggregator, autoblog, or RSS parsing.
Content Pilot – Autoblogging & Affiliate Marketing Suite
wp-content-pilot
Automatically post contents, create news feeds, import and display unlimited RSS feeds from various sources in a few clicks!
WPeMatico RSS Feed Fetcher
wpematico
WPeMatico is autoblogging in the blink of an eye! On complete autopilot, WPeMatico delivers fresh content to your site regularly!
Auto Robot – WP Autoblogging and RSS Feed News Aggregator
auto-robot
Auto blogging and generate WordPress posts automatically from OpenAI ChatGPT, RSS Feed, Instagram, Youtube, Facebook, Twitter, Vimeo, Flickr and etc.
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Developer Profile
37 plugins · 2.2M total installs
How We Detect RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feedzy-rss-feeds/css/feedzy-rss-feeds.css/wp-content/plugins/feedzy-rss-feeds/css/feedzy-rss-feeds-public.css/wp-content/plugins/feedzy-rss-feeds/css/feedzy-rss-feeds-elementor.css/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds.js/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds-public.js/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds-gutenberg.js/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds-elementor.js/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds.js/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds-public.js/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds-gutenberg.js/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds-elementor.jsfeedzy-rss-feeds/css/feedzy-rss-feeds.css?ver=feedzy-rss-feeds/css/feedzy-rss-feeds-public.css?ver=feedzy-rss-feeds/css/feedzy-rss-feeds-elementor.css?ver=feedzy-rss-feeds/js/feedzy-rss-feeds.js?ver=feedzy-rss-feeds/js/feedzy-rss-feeds-public.js?ver=feedzy-rss-feeds/js/feedzy-rss-feeds-gutenberg.js?ver=feedzy-rss-feeds/js/feedzy-rss-feeds-elementor.js?ver=HTML / DOM Fingerprints
feedzy-rss-feeddata-feedzy-idfeedzy_rss_feeds_paramsfeedzy_rss_feeds_public_params/wp-json/feedzy/v1/feed/