
LH RDF Security & Risk Analysis
wordpress.org/plugins/lh-rdfThis plugin publishes your weblog as RDF in multiple formats (xml, turtle, json etc). Mapping WordPress objects to the major ontologies.
Is LH RDF Safe to Use in 2026?
Generally Safe
Score 85/100LH RDF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lh-rdf" plugin v1.21 exhibits a mixed security posture. On the positive side, it has a zero attack surface from common entry points like AJAX handlers, REST API routes, shortcodes, and cron events, and no known CVEs or past vulnerabilities. This suggests a potentially well-hardened plugin against external exploitation vectors. However, the static analysis reveals significant internal code concerns. The presence of dangerous functions like `exec`, `proc_open`, and `unserialize` is a major red flag, indicating potential for arbitrary code execution if user-supplied data is not meticulously validated before being passed to these functions. Furthermore, the low rate of properly escaped output (23%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into pages viewed by other users. While taint analysis found no critical or high severity flows, the single unsanitized path flow warrants attention given the presence of dangerous functions. The lack of nonce checks and limited capability checks also contribute to potential security weaknesses.
Key Concerns
- Presence of dangerous functions (exec, proc_open, unserialize)
- Low output escaping rate (23%)
- Lack of nonce checks
- Limited capability checks (2)
- Taint flow with unsanitized path
- SQL queries not using prepared statements (25%)
LH RDF Security Vulnerabilities
LH RDF Release Timeline
LH RDF Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
LH RDF Attack Surface
WordPress Hooks 11
Maintenance & Trust
LH RDF Maintenance & Trust
Maintenance Signals
Community Trust
LH RDF Alternatives
LH Relationships
lh-relationships
This plugin allows allows the creation and publishing of triple relationships in RDF format.
Disable Feeds
disable-feeds
Disables all RSS/Atom/RDF feeds on your WordPress site.
Disable RSS, RDF, and Atom Feeds
disable-rss-rdf-atom-feeds
Disable all RSS, RDF, and Atom feeds on your WordPress site with the option to control behavior such as redirection or issuing a 404 error.
Feeds in Theme plugin
feeds-in-theme
Creates 4 feeds :
EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more
embedpress
EmbedPress lets you embed videos, pages, social feeds, embed PDF 3D flipbooks & other content on WordPress without coding & enhance storytelling.
LH RDF Developer Profile
89 plugins · 15K total installs
How We Detect LH RDF
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lh-rdf/context/content/visualizer.css/wp-content/plugins/lh-rdf/context/content/visualizer-skin.css/wp-content/plugins/lh-rdf/context/content/visualizer-ie6.css/wp-content/plugins/lh-rdf/context/scripts/visualizer_compiled_min.js/wp-content/plugins/lh-rdf/context/example/example_schema.json/wp-content/plugins/lh-rdf/context/scripts/visualizer_compiled_min.jsvisualizer_compiled_min.js?foo=barHTML / DOM Fingerprints
Visualizer CSS filesVisualizer IE6 CSS fileVisualizer release version script include fileVisualizer example code+3 morevisualizer_canvasid="visualizer_canvas"VisualizerAppapp