RSS Feeds News Blocks Security & Risk Analysis

wordpress.org/plugins/rss-feed-news-blocks-free

Show RSS Feed on your posts and pages with shortcode to show and display single and multiple RSS feeds blocks like Popurls, Alltop, Netvibes.

100 active installs v1.2.8 PHP + WP 2.7+ Updated Mar 28, 2017
rssrss-aggregatorrss-feedrss-pluginwp-rss-retriever
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RSS Feeds News Blocks Safe to Use in 2026?

Generally Safe

Score 85/100

RSS Feeds News Blocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "rss-feed-news-blocks-free" plugin v1.2.8 demonstrates a generally strong security posture based on the provided static analysis. The absence of dangerous functions, proper use of prepared statements for SQL queries, and complete output escaping are all positive indicators. Furthermore, the lack of any recorded vulnerabilities, past or present, suggests a history of secure development and maintenance.

However, the analysis does highlight a few areas that, while not indicating immediate critical flaws, could be improved for a more robust security profile. The presence of a shortcode and a cron event as potential entry points, combined with the complete absence of nonce checks and capability checks, represents a notable area of concern. While the current data doesn't show exploitable flows, this lack of authorization mechanisms on these entry points leaves the plugin vulnerable to potential CSRF or unauthorized execution if a future vulnerability were introduced or if a user interacts with these features in an unexpected way.

In conclusion, the plugin is currently in a good state from a security perspective, evidenced by its clean vulnerability history and sound coding practices regarding SQL and output handling. The primary weakness lies in the lack of robust authorization checks on its entry points, specifically the shortcode and cron event. Addressing this would elevate its security posture from good to excellent, ensuring protection against a wider range of potential attacks.

Key Concerns

  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
None known

RSS Feeds News Blocks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

RSS Feeds News Blocks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

RSS Feeds News Blocks Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[newsblocks] RSS_news_blocks.php:52
WordPress Hooks 4
actioninitRSS_news_blocks.php:17
actionrfnb_cronRSS_news_blocks.php:26
actionwp_enqueue_scriptsRSS_news_blocks.php:38
filterwp_feed_cache_transient_lifetimeRSS_news_blocks.php:113

Scheduled Events 1

rfnb_cron
Maintenance & Trust

RSS Feeds News Blocks Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedMar 28, 2017
PHP min version
Downloads10K

Community Trust

Rating72/100
Number of ratings5
Active installs100
Developer Profile

RSS Feeds News Blocks Developer Profile

onigetoc

3 plugins · 350 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RSS Feeds News Blocks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rss-feed-news-blocks-free/css/columns.css/wp-content/plugins/rss-feed-news-blocks-free/css/rfnb.css/wp-content/plugins/rss-feed-news-blocks-free/img/feed-icon.png

HTML / DOM Fingerprints

CSS Classes
rfnb_mergerfnb_columnone_columnone_halfone_thirdone_fourthone_fifthone_sixth+9 more
Data Attributes
data-rfnb-columndata-rfnb-itemsdata-rfnb-excerptdata-rfnb-readmoredata-rfnb-newwindowdata-rfnb-columns+10 more
JS Globals
rfnb_data
Shortcode Output
<div class="clear"></div><div class="clear" style="color: #ccc;font-size: 13px;">Powered by: <a href="http://www.scriptsmashup.com/product/rss-feeds-news-blocks" target="_blank">RSS Feed News Blocks</a></div>
FAQ

Frequently Asked Questions about RSS Feeds News Blocks