
Feng Custom Security & Risk Analysis
wordpress.org/plugins/feng-custom晨风自定义,友情链接及RSS聚合功能,图片灯箱及网页特效包含节日氛围、雪花飘落、底部运行天数、网页灰色、输入框七彩光子特效等等。
Is Feng Custom Safe to Use in 2026?
Generally Safe
Score 85/100Feng Custom has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The feng-custom plugin v1.2.4 demonstrates some positive security practices, including the absence of known vulnerabilities and a commitment to using prepared statements for SQL queries. The static analysis reveals a small attack surface with all identified entry points appearing to have authentication checks, which is a significant strength. Additionally, there are no recorded critical or high severity taint flows, and no dangerous functions were identified.
However, there are notable concerns. The low percentage of properly escaped output (22%) is a significant weakness, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the number of file operations is moderate, the lack of detailed analysis in taint flows makes it difficult to assess the security of these operations. The presence of nonce checks and capability checks is positive, but their limited number (2 each) may not cover all potential attack vectors, especially considering the 125 output points. The plugin's history of no vulnerabilities is reassuring but doesn't guarantee future safety, especially with the identified output escaping issues.
In conclusion, while the plugin has a clean vulnerability history and good SQL practices, the substantial lack of output escaping is a major security flaw that significantly elevates the risk. The plugin's security posture is mixed, with a strong foundation in some areas but critical weaknesses in others that require immediate attention.
Key Concerns
- Low output escaping percentage
- Limited number of nonce and capability checks
Feng Custom Security Vulnerabilities
Feng Custom Code Analysis
Output Escaping
Feng Custom Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Scheduled Events 1
Maintenance & Trust
Feng Custom Maintenance & Trust
Maintenance Signals
Community Trust
Feng Custom Alternatives
Subscribe Button by AddToAny
add-to-any-subscribe
Help visitors subscribe to your blog using email or any feed reader, such as Feedly, The Old Reader, Yahoo!, AOL, and many more feed services.
Widget Box Lite
widget-box-lite
A toolbox of great widgets for your daily blogging. Display recent posts, social links, and much more. Designed for Theme4Press themes
Chameleon
chameleon
A great WordPress plugin which helps you to choose a unique style for your favorite plugins and themes.
Hello EleColor
hello-elecolor-change-hello-elementor-link-color
Customize link colors for the Hello Elementor theme with ease.
Preview Link Generator
preview-link-generator
Preview Link Generator is a plugin to help you create demo/preview links for your WordPress themes, plugins, HTML templates preview.
Feng Custom Developer Profile
1 plugin · 100 total installs
How We Detect Feng Custom
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feng-custom/admin/css/admin.css/wp-content/plugins/feng-custom/admin/js/admin.js/wp-content/plugins/feng-custom/admin/js/admin.jsfeng-custom/admin/css/admin.css?ver=feng-custom/admin/js/admin.js?ver=HTML / DOM Fingerprints
feng-custom-wrap<!-- feng-custom -->data-fengcustomfeng_custom_ajax_obj