Featured Image in RSS Feed by MailerLite Security & Risk Analysis

wordpress.org/plugins/mailerlite-featured-image-in-rss-feed

This plugin automatically adds featured images of your posts into the RSS feed.

2K active installs v1.0.9 PHP 5.3+ WP 4.0+ Updated Oct 10, 2024
featured-imagefeedmailerliterssrss-feed
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Featured Image in RSS Feed by MailerLite Safe to Use in 2026?

Generally Safe

Score 92/100

Featured Image in RSS Feed by MailerLite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The security posture of the "mailerlite-featured-image-in-rss-feed" plugin v1.0.9 appears to be quite strong based on the static analysis. The plugin has a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential for external exploitation. The code signals are also positive, with no dangerous functions used, all SQL queries employing prepared statements, no file operations or external HTTP requests, and no apparent taint flows that would indicate critical or high-severity vulnerabilities. The absence of any recorded CVEs further reinforces this perception of a secure plugin.

However, there are a few areas that warrant attention. The low percentage of properly escaped output (17%) is a notable concern. This could leave the plugin susceptible to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is rendered directly in the output without adequate sanitization. Additionally, the lack of any nonce checks or capability checks for any entry points (though the attack surface is currently zero) means that if any new entry points were to be introduced in future updates, they might not be secured by default, requiring manual intervention.

Overall, the plugin demonstrates good development practices by avoiding common pitfalls like raw SQL and dangerous functions. The vulnerability history is excellent, suggesting a history of secure development. The primary weakness lies in output escaping, which should be addressed to achieve a more robust security profile. If the attack surface were to grow, the absence of built-in checks for nonces and capabilities would become a more significant risk.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Featured Image in RSS Feed by MailerLite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Featured Image in RSS Feed by MailerLite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

17% escaped6 total outputs
Attack Surface

Featured Image in RSS Feed by MailerLite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuincludes\admin\class.settings.php:29
actionadmin_initincludes\admin\class.settings.php:30
filterplugin_action_linksincludes\admin\plugins.php:28
filterplugin_row_metaincludes\admin\plugins.php:57
filterthe_excerpt_rssincludes\hooks.php:17
filterthe_content_feedincludes\hooks.php:18
actionadmin_enqueue_scriptsincludes\scripts.php:35
actionplugins_loadedmailerlite-featured-image-in-rss-feed.php:146
Maintenance & Trust

Featured Image in RSS Feed by MailerLite Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedOct 10, 2024
PHP min version5.3
Downloads26K

Community Trust

Rating100/100
Number of ratings1
Active installs2K
Developer Profile

Featured Image in RSS Feed by MailerLite Developer Profile

MailerLite

3 plugins · 132K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
356 days
View full developer profile
Detection Fingerprints

How We Detect Featured Image in RSS Feed by MailerLite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mailerlite-featured-image-in-rss-feed/assets/css/admin.css/wp-content/plugins/mailerlite-featured-image-in-rss-feed/assets/js/admin.js
Script Paths
/wp-content/plugins/mailerlite-featured-image-in-rss-feed/assets/js/admin.js
Version Parameters
mailerlite-featured-image-in-rss-feed/assets/css/admin.css?ver=mailerlite-featured-image-in-rss-feed/assets/js/admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Featured Image in RSS Feed by MailerLite