
Zen Feed Security & Risk Analysis
wordpress.org/plugins/mihdan-mailru-pulse-feedПлагин формирует RSS-ленту (фид), которая подходит для таких сервисов как: "Свежее и актуальное" в панели вебмастера Яндекс, "Яндекс.
Is Zen Feed Safe to Use in 2026?
Generally Safe
Score 92/100Zen Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mihdan-mailru-pulse-feed plugin version 0.8.5 demonstrates a generally good security posture based on the provided static analysis. The plugin has no identified CVEs in its history, suggesting a track record of security, or at least a lack of publicly disclosed vulnerabilities. The static analysis reveals a very small attack surface with zero identified entry points, and importantly, zero unprotected entry points. This indicates a strong reliance on WordPress's built-in authorization mechanisms and a lack of direct, unauthenticated access vectors. Furthermore, the code signals show a complete absence of dangerous functions and raw SQL queries, with all SQL queries utilizing prepared statements, which is a significant strength in preventing SQL injection vulnerabilities. However, there are some areas for improvement. While the vast majority of output is properly escaped, 74% properly escaped leaves 26% potentially unescaped. This could represent a weakness, particularly if the unescaped output involves user-supplied data, potentially leading to cross-site scripting (XSS) vulnerabilities. Additionally, the complete lack of nonce checks is a concern for an otherwise well-protected plugin, as nonces are a fundamental WordPress security measure against CSRF attacks. The presence of capability checks is positive, but their effectiveness would be enhanced by complementary nonce checks.
Key Concerns
- Unescaped output percentage is low
- No nonce checks found
Zen Feed Security Vulnerabilities
Zen Feed Code Analysis
Output Escaping
Zen Feed Attack Surface
WordPress Hooks 36
Maintenance & Trust
Zen Feed Maintenance & Trust
Maintenance Signals
Community Trust
Zen Feed Alternatives
RSS for Yandex Zen
rss-for-yandex-zen
Создание RSS-ленты для сервиса Яндекс.Дзен.
MyTracker
mytracker
Analytics and attribution system for mobile apps and websites.
Citizens Feedbacks
citizens-feedbacks
Simple citizens feedback form.
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
Zen Feed Developer Profile
11 plugins · 31K total installs
How We Detect Zen Feed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mihdan-mailru-pulse-feed/assets/js/admin.js/wp-content/plugins/mihdan-mailru-pulse-feed/assets/css/admin.css/wp-content/plugins/mihdan-mailru-pulse-feed/assets/css/feed.cssmihdan-mailru-pulse-feed/assets/js/admin.js?ver=mihdan-mailru-pulse-feed/assets/css/admin.css?ver=mihdan-mailru-pulse-feed/assets/css/feed.css?ver=HTML / DOM Fingerprints
data-pulse-component-namedata-pulse-component