RSS Block for Newsletter Security & Risk Analysis

wordpress.org/plugins/newsletter-rss-block

Adds a RSS block to the Newsletter composer to embed content in newsletters from external sources.

60 active installs v1.0.5 PHP 7.2+ WP 5.0.0+ Updated May 30, 2023
composerfeednewsletterrss
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RSS Block for Newsletter Safe to Use in 2026?

Generally Safe

Score 85/100

RSS Block for Newsletter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "newsletter-rss-block" plugin version 1.0.5 exhibits a strong security posture with a zero attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a robust security foundation. All SQL queries utilize prepared statements, indicating good data sanitization practices in that area. However, a concerning aspect is the output escaping, with only 35% of outputs being properly escaped. This leaves a significant portion of user-facing data potentially vulnerable to cross-site scripting (XSS) attacks if the unescaped data originates from user input. The plugin also lacks nonce and capability checks, which are crucial for preventing unauthorized actions and privilege escalation, especially if any functionality were to be exposed or become accessible in the future. The clean vulnerability history, with no known CVEs, is a positive indicator, suggesting the developers have maintained a secure codebase. Despite the lack of direct vulnerabilities in the provided data, the unescaped output and absence of critical security checks represent potential weaknesses that could be exploited.

Key Concerns

  • Output escaping is insufficient (35% proper)
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

RSS Block for Newsletter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

RSS Block for Newsletter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

35% escaped17 total outputs
Attack Surface

RSS Block for Newsletter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionnewsletter_register_blocksindex.php:20
Maintenance & Trust

RSS Block for Newsletter Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMay 30, 2023
PHP min version7.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

RSS Block for Newsletter Developer Profile

Stefano Lissa

14 plugins · 515K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
650 days
View full developer profile
Detection Fingerprints

How We Detect RSS Block for Newsletter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/newsletter-rss-block/rss/block.php/wp-content/plugins/newsletter-rss-block/rss/options.php/wp-content/plugins/newsletter-rss-block/rss/icon.png

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about RSS Block for Newsletter