MF2 Feeds Security & Risk Analysis

wordpress.org/plugins/mf2-feed

Add Microformats2 Feeds for WordPress

30 active installs v3.1.1 PHP 7.2+ WP 5.2+ Updated Dec 7, 2025
indiewebjf2mf2microformatsrel-alternate
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MF2 Feeds Safe to Use in 2026?

Generally Safe

Score 100/100

MF2 Feeds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The mf2-feed plugin v3.1.1 exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface points, dangerous functions, file operations, external HTTP requests, and SQL injection risks (all queries use prepared statements) is commendable. Taint analysis also shows no vulnerabilities detected, indicating no obvious paths for malicious data to reach sensitive functions. The plugin's vulnerability history being entirely clear further reinforces this positive assessment, suggesting a well-maintained and secure codebase.

While the lack of specific security checks like nonce and capability checks is noted, it's in the context of a zero-attack-surface plugin. This implies that these checks may not be necessary for the plugin's current functionality and design. The high percentage of properly escaped output is also a positive sign. Overall, this plugin appears to be robust and low-risk. However, the complete absence of these common security checks could be a point of caution if the plugin were to evolve to expose more interactive features in the future without implementing them. Despite this minor observation, the current state is very secure.

Key Concerns

  • No nonce checks found
  • No capability checks found
  • Output escaping could be more robust (80%)
Vulnerabilities
None known

MF2 Feeds Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MF2 Feeds Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped20 total outputs
Attack Surface

MF2 Feeds Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninitmf2-feed.php:15
actiondo_feed_mf2mf2-feed.php:33
actiondo_feed_jf2mf2-feed.php:34
actionwp_headmf2-feed.php:36
filterfeed_content_typemf2-feed.php:37
filtertemplate_includemf2-feed.php:39
Maintenance & Trust

MF2 Feeds Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 7, 2025
PHP min version7.2
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

MF2 Feeds Developer Profile

Matthias Pfefferle

8 plugins · 3K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
321 days
View full developer profile
Detection Fingerprints

How We Detect MF2 Feeds

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mf2-feed/includes/feed-mf2.php/wp-content/plugins/mf2-feed/includes/feed-mf2-comments.php/wp-content/plugins/mf2-feed/includes/feed-jf2.php/wp-content/plugins/mf2-feed/includes/feed-jf2-comments.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about MF2 Feeds