
Newsworthy Feed Security & Risk Analysis
wordpress.org/plugins/newsworthy-feedNewsworthy Feed enables you to get content from Newsworthy RSS feeds & save them as WP Posts.
Is Newsworthy Feed Safe to Use in 2026?
Generally Safe
Score 92/100Newsworthy Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "newsworthy-feed" plugin version 1.6 demonstrates a generally strong security posture based on the provided static analysis. The complete absence of direct attack surface entry points like AJAX handlers, REST API routes, and shortcodes is a significant strength. Furthermore, all identified SQL queries utilize prepared statements, indicating a good practice against SQL injection vulnerabilities. The high percentage of properly escaped output (89%) also suggests a conscious effort to prevent cross-site scripting (XSS) attacks. The plugin's vulnerability history is also clean, with no recorded CVEs, which is a positive indicator. However, the presence of 0 nonce checks and 0 capability checks on its identified entry points (even if currently limited) represents a notable weakness. While there are no active flows with unsanitized paths in the taint analysis, this lack of robust authorization checks creates potential vectors for privilege escalation or unauthorized actions if new entry points are introduced or if existing ones are exploited in conjunction with other vulnerabilities. The file operations and external HTTP requests, while not explicitly flagged as dangerous, should be monitored for any potential misuse. Overall, the plugin is in a good state but has a critical area for improvement regarding input validation and authorization for its functionalities.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- 1 cron event (potential hidden entry point)
- 11% of outputs not properly escaped
Newsworthy Feed Security Vulnerabilities
Newsworthy Feed Code Analysis
Output Escaping
Newsworthy Feed Attack Surface
WordPress Hooks 9
Scheduled Events 1
Maintenance & Trust
Newsworthy Feed Maintenance & Trust
Maintenance Signals
Community Trust
Newsworthy Feed Alternatives
Disable Feeds and Comments
disable-rss-feeds-and-comments
This WordPress plugin, "Disable RSS Feeds and Comments," gives you the ability to turn off both the RSS feeds and comments on pages and/or p …
Simple Custom Content
simple-custom-content
Easily add custom content to your WP Posts, Pages, and RSS Feeds.
Disable Feeds
disable-feeds
Disables all RSS/Atom/RDF feeds on your WordPress site.
GN Publisher: Google News Compatible RSS Feeds
gn-publisher
GN Publisher makes RSS feeds that comply with the Google News RSS Feed Technical Requirements for including your site in the Google News.
Disable Feeds WP
disable-feeds-wp
Disables all RSS/Atom/RDF feeds on your WordPress site.
Newsworthy Feed Developer Profile
1 plugin · 20 total installs
How We Detect Newsworthy Feed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/newsworthy-feed/attachments/jquery.chosen.min.css/wp-content/plugins/newsworthy-feed/attachments/nwaif_style.css/wp-content/plugins/newsworthy-feed/attachments/jquery.chosen.min.js/wp-content/plugins/newsworthy-feed/attachments/nwaif_script.js/wp-content/plugins/newsworthy-feed/attachments/nwaif_verify.js/wp-content/plugins/newsworthy-feed/attachments/jquery.chosen.min.js/wp-content/plugins/newsworthy-feed/attachments/nwaif_script.js/wp-content/plugins/newsworthy-feed/attachments/nwaif_verify.js/wp-content/plugins/newsworthy-feed/attachments/jquery.chosen.min.css?ver=/wp-content/plugins/newsworthy-feed/attachments/nwaif_style.css?ver=/wp-content/plugins/newsworthy-feed/attachments/jquery.chosen.min.js?ver=/wp-content/plugins/newsworthy-feed/attachments/nwaif_script.js?ver=/wp-content/plugins/newsworthy-feed/attachments/nwaif_verify.js?ver=HTML / DOM Fingerprints
data-nwaif-feed-keynwaifPluginVersion[newsworthy_feed][nwaif_feed]