
FriendFeed API Core Security & Risk Analysis
wordpress.org/plugins/friendfeed-api-coreDoes little else but load the core FriendFeed API library for any Plugin that wants to utilize it.
Is FriendFeed API Core Safe to Use in 2026?
Generally Safe
Score 85/100FriendFeed API Core has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The friendfeed-api-core plugin, version 0.1, presents a mixed security posture. On the positive side, it boasts zero known CVEs, an absence of SQL injection risks due to exclusively using prepared statements, and a clean slate regarding external vulnerability history. Furthermore, static analysis reveals no direct attack vectors through AJAX, REST API, shortcodes, or cron events, suggesting a well-contained plugin in terms of entry points. However, significant concerns arise from the code signals. The presence of the 'assert' function, while not immediately exploitable without further context, is a red flag. More critically, 100% of its output is unescaped, and there's a high likelihood of unsanitized paths identified in the taint analysis, indicating potential for cross-site scripting (XSS) vulnerabilities if the data processed is user-controlled or comes from untrusted sources. The lack of any nonce or capability checks on its (currently zero) entry points is also a weakness, as it implies no built-in protection against CSRF or unauthorized access should entry points be added in future versions without proper security implemented.
Key Concerns
- Unescaped output (100%)
- Flow with unsanitized paths
- Dangerous function: assert
- Missing nonce checks (0 entry points)
- Missing capability checks (0 entry points)
FriendFeed API Core Security Vulnerabilities
FriendFeed API Core Release Timeline
FriendFeed API Core Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
FriendFeed API Core Attack Surface
WordPress Hooks 1
Maintenance & Trust
FriendFeed API Core Maintenance & Trust
Maintenance Signals
Community Trust
FriendFeed API Core Alternatives
Meta for WooCommerce
facebook-for-woocommerce
Get the Official Meta for WooCommerce plugin for powerful ways to help grow your business.
PixelYourSite – Your smart PIXEL (TAG) & API Manager
pixelyoursite
Add Meta Pixel with Conversion API, Google Analytics (GA4) + Consent Mode, Google Tag Manager, and Head & Footer scripts.
Meta pixel for WordPress
official-facebook-pixel
Grow your business with Meta for WordPress!
WooCommerce Legacy REST API
woocommerce-legacy-rest-api
The WooCommerce Legacy REST API, which is now part of WooCommerce itself but will be removed in WooCommerce 9.0.
Instant Indexing for Google
fast-indexing-api
A very efficient yet simple plugin to take care of your indexing woos and helps get your content crawled by search bots instantly.
FriendFeed API Core Developer Profile
20 plugins · 21K total installs
How We Detect FriendFeed API Core
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/friendfeed-api-core/friendfeed-api/friendfeed.phpHTML / DOM Fingerprints
formdata-friendfeed-api-version