Add RSS feed Link to Single Posts (Promote RSS Link) Security & Risk Analysis

wordpress.org/plugins/rss-feed-link-to-post

Add/promote RSS feed link to every post. Right now, the rss link appears at the bottom of every post but more customization will be available on reque …

0 active installs v1.3.1 PHP + WP 3.1+ Updated Jul 7, 2020
rssrss-feedrss-feed-linkrss-link-to-post
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Add RSS feed Link to Single Posts (Promote RSS Link) Safe to Use in 2026?

Generally Safe

Score 85/100

Add RSS feed Link to Single Posts (Promote RSS Link) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "rss-feed-link-to-post" plugin version 1.3.1 exhibits a strong overall security posture in terms of its attack surface and vulnerability history. The static analysis reveals no apparent AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, all identified entry points are reported as protected. Furthermore, there are no recorded CVEs, indicating a history of stability and likely proactive patching or a lack of exploitable historical vulnerabilities. The code also appears to avoid dangerous functions and only uses prepared statements for its SQL queries, which are positive security indicators.

However, a significant concern arises from the output escaping analysis. With 13 total outputs and 0% properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data that is not properly escaped before being displayed to users or within the WordPress admin area could be leveraged by attackers to inject malicious scripts. The taint analysis showing zero flows is a positive sign that there are no immediately obvious unsanitized data flows identified by the analysis, but this is heavily overshadowed by the lack of output escaping.

In conclusion, while the plugin has a clean vulnerability history and a limited attack surface with good practices around SQL and dangerous functions, the complete absence of output escaping is a critical weakness. This single oversight makes the plugin highly susceptible to XSS attacks, which could have serious consequences for site security. The plugin's strengths are significantly undermined by this one critical area of neglect.

Key Concerns

  • No output escaping
Vulnerabilities
None known

Add RSS feed Link to Single Posts (Promote RSS Link) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Add RSS feed Link to Single Posts (Promote RSS Link) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped13 total outputs
Attack Surface

Add RSS feed Link to Single Posts (Promote RSS Link) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menurss-feed-link-to-post-inthiscode.php:16
actionadmin_initrss-feed-link-to-post-inthiscode.php:46
filterthe_contentrss-feed-link-to-post-inthiscode.php:192
Maintenance & Trust

Add RSS feed Link to Single Posts (Promote RSS Link) Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJul 7, 2020
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Add RSS feed Link to Single Posts (Promote RSS Link) Developer Profile

inthiscode

6 plugins · 190 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Add RSS feed Link to Single Posts (Promote RSS Link)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
promote
FAQ

Frequently Asked Questions about Add RSS feed Link to Single Posts (Promote RSS Link)