Plugin Name: oQey Rss Security & Risk Analysis

wordpress.org/plugins/oqey-rss

oQey Rss plugin is a Wordpress Plugin that allows see images on your rss feed.

10 active installs v0.1 PHP + WP 2.9.0+ Updated Feb 7, 2011
cool-rsscustom-rssimagesoqey-rssrss
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Plugin Name: oQey Rss Safe to Use in 2026?

Generally Safe

Score 85/100

Plugin Name: oQey Rss has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The oqey-rss plugin v0.1 presents a mixed security posture. On the positive side, the static analysis shows a complete lack of dangerous functions, no file operations, no external HTTP requests, and importantly, all SQL queries are properly prepared, which is a strong defense against SQL injection. The absence of any recorded vulnerabilities in its history is also a positive indicator. However, the analysis reveals significant concerns regarding output escaping. With 100% of outputs not being properly escaped, this plugin poses a substantial risk of Cross-Site Scripting (XSS) vulnerabilities.

The lack of any identified taint flows, dangerous functions, or SQL injection vectors in the static analysis is encouraging. Similarly, the absence of historical CVEs suggests a good development history or a lack of targeted exploitation. Nevertheless, the unescaped output is a critical weakness that can be easily exploited, especially given the plugin's apparent lack of robust authentication or capability checks on its entry points, which are also non-existent.

Key Concerns

  • Unescaped output detected
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

Plugin Name: oQey Rss Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Plugin Name: oQey Rss Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Plugin Name: oQey Rss Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Plugin Name: oQey Rss Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterthe_contentoqeyrss.php:23
Maintenance & Trust

Plugin Name: oQey Rss Maintenance & Trust

Maintenance Signals

WordPress version tested2.9.2
Last updatedFeb 7, 2011
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Plugin Name: oQey Rss Developer Profile

oQeySites

5 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Plugin Name: oQey Rss

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
oqeyimage
FAQ

Frequently Asked Questions about Plugin Name: oQey Rss