
JSON feed Security & Risk Analysis
wordpress.org/plugins/json-feedPretty simple, really. Adds a new type of feed you can subscribe to. Simply
Is JSON feed Safe to Use in 2026?
Generally Safe
Score 85/100JSON feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'json-feed' v1.3 plugin presents a mixed security picture. On the positive side, static analysis reveals no identified attack surface points, no dangerous functions, and all SQL queries utilize prepared statements. The vulnerability history is also clear, with no known CVEs recorded, suggesting a history of good security practices or limited exposure. However, a significant concern arises from the output escaping. With 2 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed by the plugin that originates from user input or external sources could potentially be manipulated to inject malicious scripts, impacting users visiting the site or administrators managing the plugin.
Key Concerns
- All outputs are unescaped
JSON feed Security Vulnerabilities
JSON feed Code Analysis
Output Escaping
JSON feed Attack Surface
WordPress Hooks 2
Maintenance & Trust
JSON feed Maintenance & Trust
Maintenance Signals
Community Trust
JSON feed Alternatives
JSON Feed (jsonfeed.org)
jsonfeed
Adds feeds in JSON Feed format.
Feed JSON
feed-json
Adds a new type of feed you can subscribe to.
JSON Feeder
json-feeder
Adds a feed based on the jsonfeed.org standard that one can subscribe to or parse.
Feed JSON
tabletize-json-connector
Expose Wordpress posts to be used by a Tabletize data source.
WP API JSON READER
wp-api-json-reader
Get and show posts from an other WP website which have installed the WP REST API and provide json feeds via the API
JSON feed Developer Profile
5 plugins · 240 total installs
How We Detect JSON feed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
/wp-json/