Zen Feed Security & Risk Analysis

wordpress.org/plugins/mihdan-mailru-pulse-feed

Плагин формирует RSS-ленту (фид), которая подходит для таких сервисов как: "Свежее и актуальное" в панели вебмастера Яндекс, "Яндекс.

500 active installs v0.8.5 PHP 7.4+ WP 5.3+ Updated Sep 28, 2024
feedmailrupulsevkzen
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Zen Feed Safe to Use in 2026?

Generally Safe

Score 92/100

Zen Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The mihdan-mailru-pulse-feed plugin version 0.8.5 demonstrates a generally good security posture based on the provided static analysis. The plugin has no identified CVEs in its history, suggesting a track record of security, or at least a lack of publicly disclosed vulnerabilities. The static analysis reveals a very small attack surface with zero identified entry points, and importantly, zero unprotected entry points. This indicates a strong reliance on WordPress's built-in authorization mechanisms and a lack of direct, unauthenticated access vectors. Furthermore, the code signals show a complete absence of dangerous functions and raw SQL queries, with all SQL queries utilizing prepared statements, which is a significant strength in preventing SQL injection vulnerabilities. However, there are some areas for improvement. While the vast majority of output is properly escaped, 74% properly escaped leaves 26% potentially unescaped. This could represent a weakness, particularly if the unescaped output involves user-supplied data, potentially leading to cross-site scripting (XSS) vulnerabilities. Additionally, the complete lack of nonce checks is a concern for an otherwise well-protected plugin, as nonces are a fundamental WordPress security measure against CSRF attacks. The presence of capability checks is positive, but their effectiveness would be enhanced by complementary nonce checks.

Key Concerns

  • Unescaped output percentage is low
  • No nonce checks found
Vulnerabilities
None known

Zen Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Zen Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
63 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

74% escaped85 total outputs
Attack Surface

Zen Feed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 36
filterrender_block_core/gallerysrc\class-gutenberg.php:20
actioninitsrc\class-main.php:241
actioninitsrc\class-main.php:242
actionthe_seo_framework_after_front_initsrc\class-main.php:245
filterwpseo_include_rss_footersrc\class-main.php:248
actiontemplate_redirectsrc\class-main.php:251
actionafter_setup_themesrc\class-main.php:254
filterdefault_post_metadatasrc\class-main.php:263
filterdefault_term_metadatasrc\class-main.php:264
actionpre_get_postssrc\class-main.php:266
filterposts_wheresrc\class-main.php:267
filterplugin_action_linkssrc\class-main.php:269
actionadd_meta_boxessrc\class-main.php:270
actionsave_postsrc\class-main.php:271
actioncategory_edit_formsrc\class-main.php:272
actionedited_categorysrc\class-main.php:273
actionupgrader_process_completesrc\class-main.php:274
filteradmin_footer_textsrc\class-main.php:275
filtermihdan_mailru_pulse_feed_item_excerptsrc\class-main.php:277
filtermihdan_mailru_pulse_feed_item_contentsrc\class-main.php:278
filtermihdan_mailru_pulse_feed_item_contentsrc\class-main.php:279
filtermihdan_mailru_pulse_feed_item_contentsrc\class-main.php:280
filtermihdan_mailru_pulse_feed_item_contentsrc\class-main.php:281
filtermihdan_mailru_pulse_feed_itemsrc\class-main.php:282
filtermihdan_mailru_pulse_feed_itemsrc\class-main.php:283
actionadmin_enqueue_scriptssrc\class-main.php:284
actionwp_loadedsrc\class-main.php:286
filterimagify_allow_picture_tags_for_webpsrc\class-main.php:292
actionwp_headsrc\class-main.php:294
actionadmin_enqueue_scriptssrc\class-options.php:50
actionadmin_initsrc\class-options.php:53
actionadmin_menusrc\class-options.php:56
actioninitsrc\class-settings.php:73
actioninitsrc\class-settings.php:74
filterinstall_plugins_nonmenu_tabssrc\class-settings.php:75
actionadmin_enqueue_scriptssrc\class-settings.php:77
Maintenance & Trust

Zen Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 28, 2024
PHP min version7.4
Downloads19K

Community Trust

Rating100/100
Number of ratings18
Active installs500
Developer Profile

Zen Feed Developer Profile

mihdan

11 plugins · 31K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
165 days
View full developer profile
Detection Fingerprints

How We Detect Zen Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mihdan-mailru-pulse-feed/assets/js/admin.js/wp-content/plugins/mihdan-mailru-pulse-feed/assets/css/admin.css/wp-content/plugins/mihdan-mailru-pulse-feed/assets/css/feed.css
Version Parameters
mihdan-mailru-pulse-feed/assets/js/admin.js?ver=mihdan-mailru-pulse-feed/assets/css/admin.css?ver=mihdan-mailru-pulse-feed/assets/css/feed.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-pulse-component-namedata-pulse-component
FAQ

Frequently Asked Questions about Zen Feed