
JSON Feed (jsonfeed.org) Security & Risk Analysis
wordpress.org/plugins/jsonfeedAdds feeds in JSON Feed format.
Is JSON Feed (jsonfeed.org) Safe to Use in 2026?
Generally Safe
Score 92/100JSON Feed (jsonfeed.org) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "jsonfeed" plugin v1.4.5 exhibits an excellent security posture based on the provided static analysis. The absence of any identifiable attack surface points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits potential entry vectors for attackers. Furthermore, the code signals indicate robust security practices, with no dangerous functions identified, all SQL queries utilizing prepared statements, and a high percentage of output properly escaped. The lack of file operations, external HTTP requests, and the absence of nonce and capability checks (given the zero attack surface) also contribute to a strong defense. The taint analysis further reinforces this positive outlook, showing no identified vulnerabilities of any severity. The plugin's history of zero known CVEs, with no currently unpatched vulnerabilities, further underscores its reliability and secure development. While the absence of explicit nonce and capability checks might seem like a concern in other contexts, it is a direct consequence of the plugin not exposing any user-facing entry points that would typically require such protections. The plugin's strengths lie in its minimal attack surface and adherence to secure coding practices. There are no apparent weaknesses based on this analysis.
JSON Feed (jsonfeed.org) Security Vulnerabilities
JSON Feed (jsonfeed.org) Code Analysis
Output Escaping
JSON Feed (jsonfeed.org) Attack Surface
WordPress Hooks 6
Maintenance & Trust
JSON Feed (jsonfeed.org) Maintenance & Trust
Maintenance Signals
Community Trust
JSON Feed (jsonfeed.org) Alternatives
JSON Feeder
json-feeder
Adds a feed based on the jsonfeed.org standard that one can subscribe to or parse.
Feed JSON
feed-json
Adds a new type of feed you can subscribe to.
JSON feed
json-feed
Pretty simple, really. Adds a new type of feed you can subscribe to. Simply
Pinecast WordPress Sync
pinecast-wp-sync
This plugin allows you to sync your Pinecast podcast (or any JSONFeed-compatible podcast) with your WordPress blog.
Feed JSON
tabletize-json-connector
Expose Wordpress posts to be used by a Tabletize data source.
JSON Feed (jsonfeed.org) Developer Profile
1 plugin · 1K total installs
How We Detect JSON Feed (jsonfeed.org)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.