MediaRSS with Post Thumbnail Security & Risk Analysis

wordpress.org/plugins/mediarss-with-post-thumbnail

with thumbnail, thumbnail, thumbnails, post thumbnail Requires at least: 2.7 Tested up to: 2.9 Adds <media> tags to your feeds with post thumbn &hellip;

20 active installs v0.1 PHP + WP + Updated Apr 3, 2010
feedfeedsmediarssmrssrss
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MediaRSS with Post Thumbnail Safe to Use in 2026?

Generally Safe

Score 85/100

MediaRSS with Post Thumbnail has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The "mediarss-with-post-thumbnail" plugin v0.1 exhibits a seemingly strong initial security posture with no reported vulnerabilities and a clean slate in terms of known CVEs. The static analysis further reinforces this impression by reporting zero AJAX handlers, REST API routes, shortcodes, or cron events, indicating a minimal attack surface. Furthermore, the absence of dangerous functions and file operations is positive. However, a critical concern arises from the output escaping analysis, where 100% of the five detected outputs are not properly escaped. This represents a significant risk for Cross-Site Scripting (XSS) vulnerabilities, as malicious code could be injected into the content displayed by the plugin. Despite the absence of taint analysis findings, the lack of output sanitization is a glaring weakness that could be exploited by an attacker. The plugin's vulnerability history is empty, which could suggest good development practices or simply that the plugin is new and has not been thoroughly scrutinized or targeted yet. The lack of capability checks and nonce checks, while not directly flagged as an issue due to the limited attack surface reported, could become problematic if new entry points are added without corresponding security measures.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

MediaRSS with Post Thumbnail Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MediaRSS with Post Thumbnail Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

MediaRSS with Post Thumbnail Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Attack Surface

MediaRSS with Post Thumbnail Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actiontemplate_redirectmrss-with-thumbnail.php:16
actionrss2_nsmrss-with-thumbnail.php:25
actionrss2_itemmrss-with-thumbnail.php:27
filterwp_get_attachment_linkmrss-with-thumbnail.php:46
Maintenance & Trust

MediaRSS with Post Thumbnail Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedApr 3, 2010
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

MediaRSS with Post Thumbnail Developer Profile

Huseyin Berberoglu

2 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MediaRSS with Post Thumbnail

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
SAMPLE CODEThe following examples are intented to show you how you can develop your own MediaRSS filters.This function will result in code like this:This function will search post_content and if it finds "[audio http://example.com/song.mp3]" it adds this to the feed:
FAQ

Frequently Asked Questions about MediaRSS with Post Thumbnail