
Postqueue Feeds Security & Risk Analysis
wordpress.org/plugins/postqueue-feedsGives you feeds for Postqueues.
Is Postqueue Feeds Safe to Use in 2026?
Generally Safe
Score 100/100Postqueue Feeds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "postqueue-feeds" v1.0 plugin reveals a seemingly robust security posture. The plugin has no identified entry points for attacks, including AJAX handlers, REST API routes, shortcodes, or cron events, and no dangerous functions are utilized. All SQL queries are properly prepared, and there are no file operations or external HTTP requests. This indicates a strong adherence to secure coding practices in these critical areas.
However, a significant concern arises from the low rate of proper output escaping, with only 25% of the total eight outputs being properly escaped. This leaves the remaining 75% vulnerable to Cross-Site Scripting (XSS) attacks, where malicious scripts could be injected and executed in the user's browser. Furthermore, the complete absence of nonce checks and capability checks on any potential entry points (though none are explicitly identified in the attack surface analysis) suggests a lack of defense-in-depth, making it reliant on the assumption that no entry points will be discovered or exploited.
The plugin's vulnerability history is clean, with no known CVEs recorded. This is a positive indicator, suggesting that the development team has historically produced secure code or that the plugin has not been a target of significant security research. However, the absence of past vulnerabilities should not be mistaken for guaranteed future security, especially given the identified output escaping issues.
Key Concerns
- Unescaped output (6 out of 8)
- Missing nonce checks
- Missing capability checks
Postqueue Feeds Security Vulnerabilities
Postqueue Feeds Code Analysis
Output Escaping
Postqueue Feeds Attack Surface
WordPress Hooks 2
Maintenance & Trust
Postqueue Feeds Maintenance & Trust
Maintenance Signals
Community Trust
Postqueue Feeds Alternatives
Disable Feeds
disable-feeds
Disables all RSS/Atom/RDF feeds on your WordPress site.
GN Publisher: Google News Compatible RSS Feeds
gn-publisher
GN Publisher makes RSS feeds that comply with the Google News RSS Feed Technical Requirements for including your site in the Google News.
Disable Feeds WP
disable-feeds-wp
Disables all RSS/Atom/RDF feeds on your WordPress site.
RSS Includes Pages
rss-includes-pages
Modifies RSS feeds so that they include pages and not just posts.
RSS Redirect & Feedburner Alternative
feedburner-alternative-and-rss-redirect
Free Feedburner Alternative and RSS Redirect plugin from follow.it.
Postqueue Feeds Developer Profile
4 plugins · 120 total installs
How We Detect Postqueue Feeds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/postqueue-feeds/inc/feed.php/wp-content/plugins/postqueue-feeds/inc/rewrite.php