ParOne Feeds Security & Risk Analysis

wordpress.org/plugins/parone

This plugin is a tool for distributing ParOne, Inc video feeds into WordPress installations. This plugin is a tool for distributing golf video supplie …

10 active installs v1.8.2 PHP 7.2+ WP 5.1+ Updated Jul 13, 2026
golfvideo
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 8, 2024
Safety Verdict

Is ParOne Feeds Safe to Use in 2026?

Generally Safe

Score 99/100

ParOne Feeds has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Nov 8, 2024Updated 1mo ago
Risk Assessment

The "parone" plugin v1.8.1 demonstrates a strong security posture in several key areas. The static analysis reveals no identified dangerous functions, 100% of SQL queries are prepared, and all output is properly escaped, indicating good development practices for preventing common vulnerabilities like SQL injection and cross-site scripting within the analyzed code. The absence of a significant attack surface, including no AJAX handlers, REST API routes, shortcodes, or cron events, further reduces the plugin's exposure to direct exploitation. However, the presence of two external HTTP requests warrants closer inspection, as these could potentially be vectors for supply chain attacks or information leakage if not handled securely. The taint analysis, while identifying one flow with unsanitized paths, did not flag any critical or high severity issues, suggesting this flow may be of lower risk or is handled by other security mechanisms not fully captured in this specific analysis. The plugin's vulnerability history shows a single past medium-severity vulnerability related to Cross-site Scripting, which was addressed by version 1.8.1. The fact that there are no currently unpatched vulnerabilities is a positive sign of ongoing maintenance and responsiveness. Overall, "parone" v1.8.1 appears to be a reasonably secure plugin, with the main areas of attention being the external HTTP requests and a full understanding of the taint flow with unsanitized paths.

Key Concerns

  • External HTTP requests present
  • Taint flow with unsanitized paths
  • Past medium vulnerability (XSS)
Vulnerabilities
1 published

ParOne Feeds Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-51874medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ParOne Feeds <= 1.17.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 8, 2024 Patched in 1.18.0 (84d)
Version History

ParOne Feeds Release Timeline

v1.18.2
v1.18.1
v1.18.0
v1.17.11 CVE
v1.17.01 CVE
v1.16.01 CVE
v1.15.121 CVE
v1.15.111 CVE
v1.15.101 CVE
v1.15.91 CVE
v1.15.81 CVE
v1.15.71 CVE
v1.15.61 CVE
v1.15.51 CVE
v1.15.41 CVE
v1.15.31 CVE
v1.15.21 CVE
v1.15.11 CVE
v1.15.01 CVE
v1.14.21 CVE
Code Analysis
Analyzed Apr 16, 2026

ParOne Feeds Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped14 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<index> (index.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ParOne Feeds Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionadmin_post_parone_video_feed_handlerincludes/parone_video_section.php:41
actionsave_postindex.php:51
actionsave_postindex.php:101
actioninitindex.php:111
actioninitindex.php:122
filterimage_size_names_chooseindex.php:133
filterscript_loader_tagindex.php:150
actionadmin_enqueue_scriptsindex.php:184
actionwp_enqueue_scriptsindex.php:185
actionadmin_initindex.php:266
actionadmin_menuindex.php:305
actioninitindex.php:323
filterquery_varsindex.php:327
actiontemplate_includeindex.php:332
Maintenance & Trust

ParOne Feeds Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJul 13, 2026
PHP min version7.2
Downloads25K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

ParOne Feeds Developer Profile

ParOne, Inc

1 plugin · 10 total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
84 days
View full developer profile
Detection Fingerprints

How We Detect ParOne Feeds

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/parone/includes/parone_shortcode_section.php/wp-content/plugins/parone/includes/parone_video_section.php/wp-content/plugins/parone/includes/ISO639.php
Script Paths
https://sdk.parone.io/parone.min.jshttps://network-videos.parone.io/network-videos.umd.js
Version Parameters
parone-sdkparone-thumbnailparone-network-videos

HTML / DOM Fingerprints

HTML Comments
<!-- AI feature test. Set to true to enabled --><!-- Prevent this function from affecting auto-saves, revisions, or non-post post types --><!-- Adjust 'post' if needed for other post types --><!-- Load translations (if any) for the plugin from the /languages/ folder. -->+5 more
Data Attributes
campaign
Shortcode Output
[parone_video_player
FAQ

Frequently Asked Questions about ParOne Feeds