
Foma's news Security & Risk Analysis
wordpress.org/plugins/foma-newsThis plugin has widget and shortcode with news from Foma.ru, Russian-language only.
Is Foma's news Safe to Use in 2026?
Generally Safe
Score 85/100Foma's news has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The foma-news v1.0.1 plugin exhibits a mixed security posture. On one hand, it demonstrates good practices by not making external HTTP requests and utilizing prepared statements for all SQL queries. The absence of known CVEs and a vulnerability history also suggests a potentially stable codebase. However, significant concerns arise from the static analysis.
The plugin's code signals reveal a concerning reliance on the deprecated and inherently insecure `create_function` function. Furthermore, a substantial portion (63%) of its output is not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce and capability checks across all entry points, despite having a shortcode, is a critical oversight that could allow unauthorized actions or information disclosure. The small attack surface with no unprotected entry points is a positive, but it is overshadowed by the internal code quality issues.
Given the lack of historical vulnerabilities and the absence of critical taint flows, the immediate risk from this specific version might appear low. However, the identified code quality issues, particularly the unescaped output and lack of authorization checks, represent significant potential weaknesses that could be exploited. Developers should prioritize addressing these code-level concerns to improve the plugin's overall security.
Key Concerns
- Deprecated and insecure create_function used
- High percentage of unescaped output (63%)
- No nonce checks on entry points
- No capability checks on entry points
Foma's news Security Vulnerabilities
Foma's news Code Analysis
Dangerous Functions Found
Output Escaping
Foma's news Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Foma's news Maintenance & Trust
Maintenance Signals
Community Trust
Foma's news Alternatives
Orthodox Calendar
orthodox-calendar
Orthodox Calendar
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Foma's news Developer Profile
3 plugins · 80 total installs
How We Detect Foma's news
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.