Native RSS Security & Risk Analysis

wordpress.org/plugins/native-rss

Changes the tag of your feeds to the language you are publishing in.

10 active installs v2.3 PHP + WP 2.7+ Updated Aug 17, 2015
feedlanguagelanguage-settingsrssrss-feed
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Native RSS Safe to Use in 2026?

Generally Safe

Score 85/100

Native RSS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The static analysis of the 'native-rss' v2.3 plugin reveals a surprisingly clean code base with no identified dangerous functions, direct SQL queries (all prepared statements), file operations, external HTTP requests, or obvious critical taint flows. The absence of any known CVEs and a clean vulnerability history further suggests a potentially secure plugin. However, the lack of any output escaping on the three identified output points is a significant concern. While there are no direct indications of cross-site scripting (XSS) due to the lack of taint analysis and known vulnerabilities, unescaped output in WordPress plugins is a common vector for such attacks, especially if dynamic data is being displayed. The plugin also has a complete absence of capability checks and nonce checks, which, in conjunction with the lack of an attack surface, might indicate that the plugin does not perform any actions that would typically require such protections. Nevertheless, this lack of security mechanisms could become a risk if the plugin's functionality changes or evolves without proper security considerations.

Key Concerns

  • No output escaping
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

Native RSS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Native RSS Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Native RSS Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterplugin_row_metanative-rss.php:48
filterplugin_action_linksnative-rss.php:49
actionadmin_initnative-rss.php:50
actionadmin_menunative-rss.php:53
Maintenance & Trust

Native RSS Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedAug 17, 2015
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Native RSS Developer Profile

tepelstreel

8 plugins · 3K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Native RSS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/native-rss/img/a5-logo.png

HTML / DOM Fingerprints

CSS Classes
a5-logo
FAQ

Frequently Asked Questions about Native RSS