Feng Custom Security & Risk Analysis

wordpress.org/plugins/feng-custom

晨风自定义,友情链接及RSS聚合功能,图片灯箱及网页特效包含节日氛围、雪花飘落、底部运行天数、网页灰色、输入框七彩光子特效等等。

100 active installs v1.2.4 PHP 7.0+ WP 5.9+ Updated Feb 25, 2024
festivalslinkrsstheme
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Feng Custom Safe to Use in 2026?

Generally Safe

Score 85/100

Feng Custom has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The feng-custom plugin v1.2.4 demonstrates some positive security practices, including the absence of known vulnerabilities and a commitment to using prepared statements for SQL queries. The static analysis reveals a small attack surface with all identified entry points appearing to have authentication checks, which is a significant strength. Additionally, there are no recorded critical or high severity taint flows, and no dangerous functions were identified.

However, there are notable concerns. The low percentage of properly escaped output (22%) is a significant weakness, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the number of file operations is moderate, the lack of detailed analysis in taint flows makes it difficult to assess the security of these operations. The presence of nonce checks and capability checks is positive, but their limited number (2 each) may not cover all potential attack vectors, especially considering the 125 output points. The plugin's history of no vulnerabilities is reassuring but doesn't guarantee future safety, especially with the identified output escaping issues.

In conclusion, while the plugin has a clean vulnerability history and good SQL practices, the substantial lack of output escaping is a major security flaw that significantly elevates the risk. The plugin's security posture is mixed, with a strong foundation in some areas but critical weaknesses in others that require immediate attention.

Key Concerns

  • Low output escaping percentage
  • Limited number of nonce and capability checks
Vulnerabilities
None known

Feng Custom Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Feng Custom Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
98
27 escaped
Nonce Checks
2
Capability Checks
2
File Operations
15
External Requests
0
Bundled Libraries
0

Output Escaping

22% escaped125 total outputs
Attack Surface

Feng Custom Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_feng_custom_refresh_rssadmin\class-feng-custom-admin.php:53
WordPress Hooks 12
actionadmin_menuadmin\class-feng-custom-admin.php:50
filterpre_option_link_manager_enabledincludes\class-feng-custom-links.php:85
filterthe_contentincludes\class-feng-custom-links.php:105
filterdisplay_post_statesincludes\class-feng-custom-links.php:126
actionfct_links_rss_cron_hookincludes\class-feng-custom-links.php:728
filtercron_schedulesincludes\class-feng-custom.php:61
actionplugins_loadedincludes\class-feng-custom.php:126
actionadmin_enqueue_scriptsincludes\class-feng-custom.php:140
actionadmin_enqueue_scriptsincludes\class-feng-custom.php:141
actionwp_enqueue_scriptsincludes\class-feng-custom.php:155
actionwp_enqueue_scriptsincludes\class-feng-custom.php:156
actionwp_enqueue_scriptsincludes\class-feng-custom.php:157

Scheduled Events 1

fct_links_rss_cron_hook
Maintenance & Trust

Feng Custom Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedFeb 25, 2024
PHP min version7.0
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Feng Custom Developer Profile

阿锋

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Feng Custom

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/feng-custom/admin/css/admin.css/wp-content/plugins/feng-custom/admin/js/admin.js
Script Paths
/wp-content/plugins/feng-custom/admin/js/admin.js
Version Parameters
feng-custom/admin/css/admin.css?ver=feng-custom/admin/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
feng-custom-wrap
HTML Comments
<!-- feng-custom -->
Data Attributes
data-fengcustom
JS Globals
feng_custom_ajax_obj
FAQ

Frequently Asked Questions about Feng Custom