FV Feedburner Replacement Security & Risk Analysis

wordpress.org/plugins/fv-feedburner-replacement

Creates a landing page for your feed subscription and out of the box working newsletter subscription form.

20 active installs v0.4.3 PHP + WP 3.5+ Updated Jun 1, 2018
feedfeedburnernewslettersubscribe
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is FV Feedburner Replacement Safe to Use in 2026?

Generally Safe

Score 85/100

FV Feedburner Replacement has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'fv-feedburner-replacement' plugin v0.4.3 demonstrates a generally positive security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events as entry points significantly limits the attack surface. Furthermore, the lack of identified dangerous functions, file operations, and external HTTP requests are also strong indicators of good security practices. The presence of nonce and capability checks, while only one each, suggests some awareness of WordPress security mechanisms.

However, the most significant concern lies in the handling of SQL queries. With 25 total queries and 0% using prepared statements, there is a high risk of SQL injection vulnerabilities. This is a critical oversight that could allow attackers to manipulate database queries. The output escaping also shows room for improvement, with only 35% properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed.

The plugin's vulnerability history is entirely clean, with no recorded CVEs. This is a very positive sign and suggests that the plugin, up to this version, has not been a target or has been developed with sufficient care. However, the absence of past vulnerabilities does not negate the risks identified in the current code analysis, particularly the raw SQL queries. In conclusion, while the plugin has a small attack surface and a clean history, the pervasive use of raw SQL queries without prepared statements presents a substantial and actionable security risk that needs immediate attention.

Key Concerns

  • Raw SQL queries without prepared statements
  • Low percentage of properly escaped output
Vulnerabilities
None known

FV Feedburner Replacement Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

FV Feedburner Replacement Release Timeline

v0.4.1
v0.4
v0.3
Code Analysis
Analyzed Mar 16, 2026

FV Feedburner Replacement Code Analysis

Dangerous Functions
0
Raw SQL Queries
25
0 prepared
Unescaped Output
20
11 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared25 total queries

Output Escaping

35% escaped31 total outputs
Attack Surface

FV Feedburner Replacement Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 27
actioninitfv-feedburner-replacement.php:20
actiongenerate_rewrite_rulesfv-feedburner-replacement.php:21
actioninitfv-feedburner-replacement.php:22
actioninitfv-feedburner-replacement.php:23
filterpre_get_postsfv-feedburner-replacement.php:25
filtertemplate_redirectfv-feedburner-replacement.php:26
filterwp_headersfv-feedburner-replacement.php:27
actionwp_headfv-feedburner-replacement.php:29
actionadmin_headfv-feedburner-replacement.php:33
actionadmin_menufv-feedburner-replacement.php:34
actionadmin_noticesfv-feedburner-replacement.php:35
filterthe_contentfv-feedburner-replacement.php:38
filterthe_excerpt_rssfv-feedburner-replacement.php:39
filterpost_linkfv-feedburner-replacement.php:40
filterpost_comments_feed_linkfv-feedburner-replacement.php:41
filterthe_permalink_rssfv-feedburner-replacement.php:42
filteroption_rss_use_excerptfv-feedburner-replacement.php:43
filterplugin_action_linksfv-feedburner-replacement.php:44
filterpost_classfv-feedburner-replacement.php:301
filterthe_postsfv-feedburner-replacement.php:760
actionwp_headfv-feedburner-replacement.php:761
actionget_edit_post_linkfv-feedburner-replacement.php:762
actionwp_before_admin_bar_renderfv-feedburner-replacement.php:764
filterthe_contentfv-feedburner-replacement.php:788
filtercomments_openfv-feedburner-replacement.php:789
filterfv_feedburner_replacement_the_contentnewsletter-bridge.php:65
filterfv_feedburner_replacement_the_contentnewsletter-bridge.php:152
Maintenance & Trust

FV Feedburner Replacement Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJun 1, 2018
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

FV Feedburner Replacement Developer Profile

FolioVision

19 plugins · 48K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
1098 days
View full developer profile
Detection Fingerprints

How We Detect FV Feedburner Replacement

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fv-feedburner-replacement/css/style.css
Version Parameters
fv-feedburner-replacement/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
fv_form
Data Attributes
name="fv_feedburner_replacement"
FAQ

Frequently Asked Questions about FV Feedburner Replacement