MediaRSS with Post Thumbnail Security & Risk Analysis
wordpress.org/plugins/mediarss-with-post-thumbnailwith thumbnail, thumbnail, thumbnails, post thumbnail Requires at least: 2.7 Tested up to: 2.9 Adds <media> tags to your feeds with post thumbn …
Is MediaRSS with Post Thumbnail Safe to Use in 2026?
Generally Safe
Score 85/100MediaRSS with Post Thumbnail has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mediarss-with-post-thumbnail" plugin v0.1 exhibits a seemingly strong initial security posture with no reported vulnerabilities and a clean slate in terms of known CVEs. The static analysis further reinforces this impression by reporting zero AJAX handlers, REST API routes, shortcodes, or cron events, indicating a minimal attack surface. Furthermore, the absence of dangerous functions and file operations is positive. However, a critical concern arises from the output escaping analysis, where 100% of the five detected outputs are not properly escaped. This represents a significant risk for Cross-Site Scripting (XSS) vulnerabilities, as malicious code could be injected into the content displayed by the plugin. Despite the absence of taint analysis findings, the lack of output sanitization is a glaring weakness that could be exploited by an attacker. The plugin's vulnerability history is empty, which could suggest good development practices or simply that the plugin is new and has not been thoroughly scrutinized or targeted yet. The lack of capability checks and nonce checks, while not directly flagged as an issue due to the limited attack surface reported, could become problematic if new entry points are added without corresponding security measures.
Key Concerns
- Unescaped output detected
MediaRSS with Post Thumbnail Security Vulnerabilities
MediaRSS with Post Thumbnail Release Timeline
MediaRSS with Post Thumbnail Code Analysis
Output Escaping
MediaRSS with Post Thumbnail Attack Surface
WordPress Hooks 4
Maintenance & Trust
MediaRSS with Post Thumbnail Maintenance & Trust
Maintenance Signals
Community Trust
MediaRSS with Post Thumbnail Alternatives
Disable Feeds
disable-feeds
Disables all RSS/Atom/RDF feeds on your WordPress site.
GN Publisher: Google News Compatible RSS Feeds
gn-publisher
GN Publisher makes RSS feeds that comply with the Google News RSS Feed Technical Requirements for including your site in the Google News.
Disable Feeds WP
disable-feeds-wp
Disables all RSS/Atom/RDF feeds on your WordPress site.
RSS Includes Pages
rss-includes-pages
Modifies RSS feeds so that they include pages and not just posts.
Feed Post Thumbnail
wp-feed-post-thumbnail
Adds MRSS namespace to the feed and uses post-thumbnail as media element in the feed. Settings available under Settings -> Reading.
MediaRSS with Post Thumbnail Developer Profile
2 plugins · 30 total installs
How We Detect MediaRSS with Post Thumbnail
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
SAMPLE CODEThe following examples are intented to show you how you can develop your own MediaRSS filters.This function will result in code like this:This function will search post_content and if it finds "[audio http://example.com/song.mp3]" it adds this to the feed: