
Add RSS feed Link to Single Posts (Promote RSS Link) Security & Risk Analysis
wordpress.org/plugins/rss-feed-link-to-postAdd/promote RSS feed link to every post. Right now, the rss link appears at the bottom of every post but more customization will be available on reque …
Is Add RSS feed Link to Single Posts (Promote RSS Link) Safe to Use in 2026?
Generally Safe
Score 85/100Add RSS feed Link to Single Posts (Promote RSS Link) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rss-feed-link-to-post" plugin version 1.3.1 exhibits a strong overall security posture in terms of its attack surface and vulnerability history. The static analysis reveals no apparent AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, all identified entry points are reported as protected. Furthermore, there are no recorded CVEs, indicating a history of stability and likely proactive patching or a lack of exploitable historical vulnerabilities. The code also appears to avoid dangerous functions and only uses prepared statements for its SQL queries, which are positive security indicators.
However, a significant concern arises from the output escaping analysis. With 13 total outputs and 0% properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data that is not properly escaped before being displayed to users or within the WordPress admin area could be leveraged by attackers to inject malicious scripts. The taint analysis showing zero flows is a positive sign that there are no immediately obvious unsanitized data flows identified by the analysis, but this is heavily overshadowed by the lack of output escaping.
In conclusion, while the plugin has a clean vulnerability history and a limited attack surface with good practices around SQL and dangerous functions, the complete absence of output escaping is a critical weakness. This single oversight makes the plugin highly susceptible to XSS attacks, which could have serious consequences for site security. The plugin's strengths are significantly undermined by this one critical area of neglect.
Key Concerns
- No output escaping
Add RSS feed Link to Single Posts (Promote RSS Link) Security Vulnerabilities
Add RSS feed Link to Single Posts (Promote RSS Link) Code Analysis
Output Escaping
Add RSS feed Link to Single Posts (Promote RSS Link) Attack Surface
WordPress Hooks 3
Maintenance & Trust
Add RSS feed Link to Single Posts (Promote RSS Link) Maintenance & Trust
Maintenance Signals
Community Trust
Add RSS feed Link to Single Posts (Promote RSS Link) Alternatives
RSS ReadMore Link
rss-feed-readmore-link
Add a readmore-link to your RSS-feed's description-text.
PowerPress Podcasting plugin by Blubrry
powerpress
No. 1 Podcasting plugin for WordPress.
Podcast Player – Your Podcasting Companion
podcast-player
Showcase your podcast only using podcasting feed url. Use widget, shortcode or editor block to display podcast player anywhere on your site.
Super RSS Reader – Add attractive RSS Feed Widget
super-rss-reader
Display any RSS feed(s) in widget with news ticker effect in multiple tabs, thumbnails, customizable color themes and more.
RSS Feed Retriever
wp-rss-retriever
The fastest RSS feeds plugin for WordPress. Includes excerpt & thumbnail image. Use as a news aggregator, autoblog, or RSS parsing.
Add RSS feed Link to Single Posts (Promote RSS Link) Developer Profile
6 plugins · 190 total installs
How We Detect Add RSS feed Link to Single Posts (Promote RSS Link)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
promote