
Multi RSS Security & Risk Analysis
wordpress.org/plugins/multi-rssMulti RSS combines and displays multiple RSS feeds as a single feed. The plugin depends on the SimplePie RSS Feed Parser for PHP.
Is Multi RSS Safe to Use in 2026?
Generally Safe
Score 85/100Multi RSS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "multi-rss" v1.0 plugin exhibits a mixed security posture. While it has a small attack surface with no AJAX handlers or REST API routes found, and a seemingly clean vulnerability history with no known CVEs, there are significant concerns within its code. The most alarming finding is the complete lack of prepared statements for all five SQL queries, making it highly susceptible to SQL injection vulnerabilities. Additionally, only 10% of output is properly escaped, posing a risk of cross-site scripting (XSS) vulnerabilities. The taint analysis reveals two critical flows with unsanitized paths, indicating potential for attackers to manipulate data or execute unintended actions.
Key Concerns
- Raw SQL queries without prepared statements
- Low output escaping percentage
- Critical taint flows with unsanitized paths
- No nonce checks
- No capability checks
Multi RSS Security Vulnerabilities
Multi RSS Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Multi RSS Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Multi RSS Maintenance & Trust
Maintenance Signals
Community Trust
Multi RSS Alternatives
Disable Feeds
disable-feeds
Disables all RSS/Atom/RDF feeds on your WordPress site.
GN Publisher: Google News Compatible RSS Feeds
gn-publisher
GN Publisher makes RSS feeds that comply with the Google News RSS Feed Technical Requirements for including your site in the Google News.
Disable Feeds WP
disable-feeds-wp
Disables all RSS/Atom/RDF feeds on your WordPress site.
RSS Includes Pages
rss-includes-pages
Modifies RSS feeds so that they include pages and not just posts.
RSS Redirect & Feedburner Alternative
feedburner-alternative-and-rss-redirect
Free Feedburner Alternative and RSS Redirect plugin from follow.it.
Multi RSS Developer Profile
1 plugin · 10 total installs
How We Detect Multi RSS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/MultiRSS/style.css/wp-content/plugins/MultiRSS/jquery.tablesorter.jsMultiRSS/style.css?ver=MultiRSS/jquery.tablesorter.js?ver=HTML / DOM Fingerprints
<a href="<span></span><img src="