
MF2 Feeds Security & Risk Analysis
wordpress.org/plugins/mf2-feedAdd Microformats2 Feeds for WordPress
Is MF2 Feeds Safe to Use in 2026?
Generally Safe
Score 100/100MF2 Feeds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mf2-feed plugin v3.1.1 exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface points, dangerous functions, file operations, external HTTP requests, and SQL injection risks (all queries use prepared statements) is commendable. Taint analysis also shows no vulnerabilities detected, indicating no obvious paths for malicious data to reach sensitive functions. The plugin's vulnerability history being entirely clear further reinforces this positive assessment, suggesting a well-maintained and secure codebase.
While the lack of specific security checks like nonce and capability checks is noted, it's in the context of a zero-attack-surface plugin. This implies that these checks may not be necessary for the plugin's current functionality and design. The high percentage of properly escaped output is also a positive sign. Overall, this plugin appears to be robust and low-risk. However, the complete absence of these common security checks could be a point of caution if the plugin were to evolve to expose more interactive features in the future without implementing them. Despite this minor observation, the current state is very secure.
Key Concerns
- No nonce checks found
- No capability checks found
- Output escaping could be more robust (80%)
MF2 Feeds Security Vulnerabilities
MF2 Feeds Code Analysis
Output Escaping
MF2 Feeds Attack Surface
WordPress Hooks 6
Maintenance & Trust
MF2 Feeds Maintenance & Trust
Maintenance Signals
Community Trust
MF2 Feeds Alternatives
Micropub
micropub
Allows you to publish to your site using Micropub clients.
Microformats 2
wp-uf2
Enhances your WordPress theme with Microformats 2 classes.
WebSub (FKA. PubSubHubbub)
pubsubhubbub
A WebSub plugin for WordPress that enables real-time publishing and subscription capabilities.
Rich Contact Widget
rich-contact-widget
A simple contact widget enhanced with microdatas & microformats tags for your local SEO
ActivityPub
activitypub
Connect your site to the Open Social Web and let millions of users follow, share, and interact with your content from Mastodon, Pixelfed, and more.
MF2 Feeds Developer Profile
8 plugins · 3K total installs
How We Detect MF2 Feeds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mf2-feed/includes/feed-mf2.php/wp-content/plugins/mf2-feed/includes/feed-mf2-comments.php/wp-content/plugins/mf2-feed/includes/feed-jf2.php/wp-content/plugins/mf2-feed/includes/feed-jf2-comments.php