Mihdan: Yandex Turbo Feed Security & Risk Analysis

wordpress.org/plugins/mihdan-yandex-turbo-feed

Mihdan: Yandex Turbo Feed by mihdan – allows you to convert your site materials into Yandex.Turbo format.

1K active installs v1.6.6 PHP 7.4+ WP 5.6+ Updated May 3, 2024
feedrssturboyandexyandex-turbo
85
A · Safe
CVEs total1
Unpatched0
Last CVEMay 6, 2024
Safety Verdict

Is Mihdan: Yandex Turbo Feed Safe to Use in 2026?

Generally Safe

Score 85/100

Mihdan: Yandex Turbo Feed has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: May 6, 2024Updated 2yr ago
Risk Assessment

The mihdan-yandex-turbo-feed v1.6.6 plugin exhibits a generally good security posture with a small attack surface and a commendable use of prepared statements for SQL queries. The absence of critical or high-severity taint flows, coupled with a lack of raw SQL queries, are positive indicators. However, the presence of a medium-severity Cross-Site Scripting (XSS) vulnerability in its history, even if currently patched, warrants caution. The code analysis shows a high percentage of properly escaped outputs, but the remaining 15% could still be a vector for XSS if they handle user-supplied data. While the plugin demonstrates strong adherence to many security best practices, the past XSS vulnerability suggests a need for ongoing vigilance and thorough testing of any user-facing output, particularly those not explicitly escaped.

Key Concerns

  • Past medium XSS vulnerability history
  • 15% of outputs not properly escaped
Vulnerabilities
1 published

Mihdan: Yandex Turbo Feed Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-4411medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Mihdan: Yandex Turbo Feed <= 1.6.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

May 6, 2024 Patched in 1.6.6 (26d)
Version History

Mihdan: Yandex Turbo Feed Release Timeline

v1.6.6Current
v1.6.5.11 CVE
v1.6.51 CVE
v1.6.41 CVE
v1.6.31 CVE
v1.6.21 CVE
v1.6.11 CVE
v1.6.01 CVE
v1.5.01 CVE
v1.4.21 CVE
v1.4.1.11 CVE
v1.4.11 CVE
v1.4.01 CVE
v1.3.81 CVE
v1.3.71 CVE
v1.3.61 CVE
v1.3.51 CVE
v1.3.41 CVE
v1.3.3.11 CVE
v1.3.31 CVE
Code Analysis
Analyzed Mar 16, 2026

Mihdan: Yandex Turbo Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
17
93 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared2 total queries

Output Escaping

85% escaped110 total outputs
Attack Surface

Mihdan: Yandex Turbo Feed Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mytf_button] includes\class-shortcodes.php:6
WordPress Hooks 53
actioninitincludes\class-bulk-edit.php:51
actionquick_edit_custom_boxincludes\class-bulk-edit.php:74
actionbulk_edit_custom_boxincludes\class-bulk-edit.php:77
actionsave_postincludes\class-bulk-edit.php:80
actionrest_api_initincludes\class-comments.php:12
actioninitincludes\class-main.php:271
filtermihdan_yandex_turbo_feed_argsincludes\class-main.php:272
filtermihdan_yandex_turbo_feed_allowable_tagsincludes\class-main.php:273
actionafter_setup_themeincludes\class-main.php:274
actionplugins_loadedincludes\class-main.php:275
filterplugin_action_linksincludes\class-main.php:276
actionmihdan_yandex_turbo_feed_itemincludes\class-main.php:278
filtermihdan_yandex_turbo_feed_item_excerptincludes\class-main.php:280
filtermihdan_yandex_turbo_feed_item_contentincludes\class-main.php:281
filterthe_content_feedincludes\class-main.php:283
filterwp_get_attachment_image_attributesincludes\class-main.php:284
actiontemplate_redirectincludes\class-main.php:286
actiontemplate_redirectincludes\class-main.php:287
actionadmin_enqueue_scriptsincludes\class-main.php:288
filteradmin_footer_textincludes\class-main.php:289
actionupgrader_process_completeincludes\class-main.php:291
actioninitincludes\class-settings.php:154
actioninitincludes\class-settings.php:155
filteracf/settings/show_adminincludes\class-settings.php:156
filtersite_status_testsincludes\class-site-health.php:21
filterdebug_informationincludes\class-site-health.php:22
actiontemplate_redirectincludes\class-template.php:48
actionmihdan_yandex_turbo_feed_channelincludes\class-template.php:49
filterrender_blockincludes\class-template.php:51
actionmihdan_yandex_turbo_feed_item_turbo_contentincludes\class-template.php:53
actionmihdan_yandex_turbo_feed_item_turbo_contentincludes\class-template.php:54
actionmihdan_yandex_turbo_feed_item_turbo_contentincludes\class-template.php:55
actionmihdan_yandex_turbo_feed_item_turbo_contentincludes\class-template.php:56
actionmihdan_yandex_turbo_feed_item_turbo_contentincludes\class-template.php:57
actionmihdan_yandex_turbo_feed_item_turbo_contentincludes\class-template.php:58
actionmihdan_yandex_turbo_feed_item_turbo_contentincludes\class-template.php:59
actionmihdan_yandex_turbo_feed_item_turbo_contentincludes\class-template.php:60
filtermihdan_yandex_turbo_feed_item_pre_get_the_contentincludes\class-template.php:62
filtermihdan_yandex_turbo_feed_item_pre_get_the_contentincludes\class-template.php:63
filtermihdan_yandex_turbo_feed_item_contentincludes\class-template.php:64
actionmihdan_yandex_turbo_feed_item_headerincludes\class-template.php:66
actionmihdan_yandex_turbo_feed_itemincludes\class-template.php:67
actionmihdan_yandex_turbo_feed_itemincludes\class-template.php:68
actionwpincludes\class-template.php:69
actionthe_seo_framework_after_front_initincludes\class-template.php:72
actiontemplate_redirectincludes\class-template.php:75
filterwpseo_include_rss_footerincludes\class-template.php:78
filterwpseo_sitemap_exclude_post_typeincludes\class-template.php:79
filterwpseo_accessible_post_typesincludes\class-template.php:80
actioninitincludes\Models\Feed.php:48
filtermihdan_yandex_turbo_feed_item_contentincludes\Models\LiteVideoEmbed.php:32
filtermihdan_yandex_turbo_feed_feed_settingsincludes\Models\WooCommerce.php:45
filtermihdan_yandex_turbo_feed_item_contentincludes\Models\WooCommerce.php:46
Maintenance & Trust

Mihdan: Yandex Turbo Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 3, 2024
PHP min version7.4
Downloads40K

Community Trust

Rating94/100
Number of ratings31
Active installs1K
Developer Profile

Mihdan: Yandex Turbo Feed Developer Profile

mihdan

12 plugins · 32K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
224 days
View full developer profile
Detection Fingerprints

How We Detect Mihdan: Yandex Turbo Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mihdan-yandex-turbo-feed/assets/css/admin.css/wp-content/plugins/mihdan-yandex-turbo-feed/assets/js/admin.js
Script Paths
/wp-content/plugins/mihdan-yandex-turbo-feed/vendor/autoload.php/wp-content/plugins/mihdan-yandex-turbo-feed/vendor/advanced-custom-fields/acf.php/wp-content/plugins/mihdan-yandex-turbo-feed/vendor/acf-multiple-taxonomy/acf-multiple-taxonomy.php/wp-content/plugins/mihdan-yandex-turbo-feed/includes/class-main.php/wp-content/plugins/mihdan-yandex-turbo-feed/includes/class-utils.php/wp-content/plugins/mihdan-yandex-turbo-feed/includes/class-settings.php+8 more
Version Parameters
mihdan-yandex-turbo-feed/assets/css/admin.css?ver=mihdan-yandex-turbo-feed/assets/js/admin.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- mihdan-yandex-turbo-feed -->
Data Attributes
turbo-contentturbo-item-titleturbo-item-descriptionturbo-item-authorturbo-item-imageturbo-item-pubdate+1 more
Shortcode Output
[yandex_turbo_feed_items][yandex_turbo_feed_item]
FAQ

Frequently Asked Questions about Mihdan: Yandex Turbo Feed