JSON Feed (jsonfeed.org) Security & Risk Analysis

wordpress.org/plugins/jsonfeed

Adds feeds in JSON Feed format.

1K active installs v1.4.5 PHP 5.6+ WP 4.9+ Updated Apr 5, 2024
feedfeedsjsonjsonfeed
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is JSON Feed (jsonfeed.org) Safe to Use in 2026?

Generally Safe

Score 92/100

JSON Feed (jsonfeed.org) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "jsonfeed" plugin v1.4.5 exhibits an excellent security posture based on the provided static analysis. The absence of any identifiable attack surface points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits potential entry vectors for attackers. Furthermore, the code signals indicate robust security practices, with no dangerous functions identified, all SQL queries utilizing prepared statements, and a high percentage of output properly escaped. The lack of file operations, external HTTP requests, and the absence of nonce and capability checks (given the zero attack surface) also contribute to a strong defense. The taint analysis further reinforces this positive outlook, showing no identified vulnerabilities of any severity. The plugin's history of zero known CVEs, with no currently unpatched vulnerabilities, further underscores its reliability and secure development. While the absence of explicit nonce and capability checks might seem like a concern in other contexts, it is a direct consequence of the plugin not exposing any user-facing entry points that would typically require such protections. The plugin's strengths lie in its minimal attack surface and adherence to secure coding practices. There are no apparent weaknesses based on this analysis.

Vulnerabilities
None known

JSON Feed (jsonfeed.org) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

JSON Feed (jsonfeed.org) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped8 total outputs
Attack Surface

JSON Feed (jsonfeed.org) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninitjsonfeed-wp.php:23
filterfeed_content_typejsonfeed-wp.php:38
filterw3tc_is_cacheable_content_typejsonfeed-wp.php:52
actionwp_headjsonfeed-wp.php:54
filterwp_headjsonfeed-wp.php:141
filterpubsubhubbub_supported_feed_typesjsonfeed-wp.php:155
Maintenance & Trust

JSON Feed (jsonfeed.org) Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 5, 2024
PHP min version5.6
Downloads56K

Community Trust

Rating100/100
Number of ratings5
Active installs1K
Developer Profile

JSON Feed (jsonfeed.org) Developer Profile

mantonr

1 plugin · 1K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect JSON Feed (jsonfeed.org)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about JSON Feed (jsonfeed.org)