
Readers From RSS 2 Blog Lite Security & Risk Analysis
wordpress.org/plugins/readers-from-rss-2-blogIncrease Your SALES And BLOG Audience By Turning Your BLOG RSS FEED Into A Powerful MARKETING Machine
Is Readers From RSS 2 Blog Lite Safe to Use in 2026?
Generally Safe
Score 85/100Readers From RSS 2 Blog Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "readers-from-rss-2-blog" v3.0.1.4 plugin exhibits a mixed security posture. While the static analysis reveals no direct external attack surface (no AJAX handlers, REST API routes, shortcodes, or cron events accessible without authentication), there are significant internal code concerns. The presence of dangerous functions like `create_function` and `unserialize` is a red flag, as these can lead to arbitrary code execution if improperly handled with user-supplied data. Furthermore, only 25% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially if any of the unsanitized taint flows lead to output. The taint analysis itself shows a concerning 100% of analyzed flows have unsanitized paths, even if classified as not critical or high severity in this specific analysis run. This suggests a general lack of input sanitization within the plugin's code. The lack of any recorded vulnerability history is a positive sign, but it does not negate the inherent risks identified in the static and taint analysis. The plugin appears to have been developed without a strong focus on security best practices regarding input validation and output escaping, despite a seemingly limited external attack vector.
Key Concerns
- Dangerous functions used (`create_function`, `unserialize`)
- Low percentage of properly escaped output (5%)
- All taint flows have unsanitized paths
- SQL queries not always using prepared statements (50%)
- No nonce checks present
- No capability checks present
Readers From RSS 2 Blog Lite Security Vulnerabilities
Readers From RSS 2 Blog Lite Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Readers From RSS 2 Blog Lite Attack Surface
WordPress Hooks 14
Maintenance & Trust
Readers From RSS 2 Blog Lite Maintenance & Trust
Maintenance Signals
Community Trust
Readers From RSS 2 Blog Lite Alternatives
RSS Redirect & Feedburner Alternative
feedburner-alternative-and-rss-redirect
Free Feedburner Alternative and RSS Redirect plugin from follow.it.
FeedPress
feedpress
Redirects all feeds to a FeedPress feed and enables realtime feed updates.
Subscribe Here Widget
subscribe-here-widget
Subscribe Here displays a visible plugin widget in the sidebar with Subscribe by Rss & Subscribe by Email(through Feedburner) options.
RSS Links Manager
rss-links-manager
Manage and customise your RSS feed links.
Feed Subscriber Stats
feed-subscriber-stats
Ever wanted to see your FeedBurner stats on the Wordpress Dashboard? Well now you can with this simple plugin. The plugin uses FeedBurner's Aware …
Readers From RSS 2 Blog Lite Developer Profile
2 plugins · 110 total installs
How We Detect Readers From RSS 2 Blog Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/readers-from-rss-2-blog/wpsmartapps-lic/images/rfr2b-logo.png/wp-content/plugins/readers-from-rss-2-blog/wpsmartapps-lic/images/upgrade.gif/wp-content/plugins/readers-from-rss-2-blog/wpsmartapps-lic/images/left-arrow.png/wp-content/plugins/readers-from-rss-2-blog/wpsmartapps-lic/images/right-arrow.png/wp-content/plugins/readers-from-rss-2-blog/wpsmartapps-lic/images/close-form.gif/wp-content/plugins/readers-from-rss-2-blog/wpsmartapps-lic/admin-pg/demo/googlereader.jpg/wp-content/plugins/readers-from-rss-2-blog/wpsmartapps-lic/images/tick.pngreaders-from-rss-2-blog/readers-from-rss-2-blog.phpHTML / DOM Fingerprints
id="global_demo"ma_feed