RSS for Yandex Zen Security & Risk Analysis

wordpress.org/plugins/rss-for-yandex-zen

Создание RSS-ленты для сервиса Яндекс.Дзен.

5K active installs v1.28 PHP 5.3+ WP 4.4+ Updated May 19, 2025
feedrssyandexyandex-zenzen
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RSS for Yandex Zen Safe to Use in 2026?

Generally Safe

Score 100/100

RSS for Yandex Zen has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The "rss-for-yandex-zen" plugin version 1.28 demonstrates a generally strong security posture based on the provided static analysis. The absence of any identified CVEs and the plugin's clean vulnerability history are positive indicators. The code analysis reveals a healthy approach to security, with no dangerous functions, a complete reliance on prepared statements for SQL queries, and a significant number of nonces and capability checks implemented. The taint analysis also shows no critical or high severity flows, suggesting that user-supplied data is being handled safely. However, there is a minor concern regarding output escaping, with approximately 29% of outputs not being properly escaped. While this may not immediately translate to a critical vulnerability, it represents a potential weakness that could be exploited in certain scenarios.

Key Concerns

  • Improper output escaping on 29% of outputs
Vulnerabilities
None known

RSS for Yandex Zen Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

RSS for Yandex Zen Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
64 escaped
Nonce Checks
3
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped90 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<rss-for-yandex-zen> (rss-for-yandex-zen.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

RSS for Yandex Zen Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionactivate_rss-for-yandex-zen/rss-for-yandex-zen.phprss-for-yandex-zen.php:53
actioninitrss-for-yandex-zen.php:85
actionadmin_enqueue_scriptsrss-for-yandex-zen.php:114
actionadmin_menurss-for-yandex-zen.php:625
actionadmin_headrss-for-yandex-zen.php:670
actionadd_meta_boxesrss-for-yandex-zen.php:680
actionsave_postrss-for-yandex-zen.php:730
actioninitrss-for-yandex-zen.php:851
filterfeed_content_typerss-for-yandex-zen.php:1228
actiontemplate_redirectrss-for-yandex-zen.php:1312
actionsave_postrss-for-yandex-zen.php:1403
Maintenance & Trust

RSS for Yandex Zen Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 19, 2025
PHP min version5.3
Downloads71K

Community Trust

Rating94/100
Number of ratings30
Active installs5K
Developer Profile

RSS for Yandex Zen Developer Profile

Flector

15 plugins · 44K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
782 days
View full developer profile
Detection Fingerprints

How We Detect RSS for Yandex Zen

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rss-for-yandex-zen/inc/animate.min.css/wp-content/plugins/rss-for-yandex-zen/inc/jquery.lettering.js/wp-content/plugins/rss-for-yandex-zen/inc/jquery.textillate.js/wp-content/plugins/rss-for-yandex-zen/inc/yzen-script.js
Script Paths
/wp-content/plugins/rss-for-yandex-zen/inc/jquery.lettering.js/wp-content/plugins/rss-for-yandex-zen/inc/jquery.textillate.js/wp-content/plugins/rss-for-yandex-zen/inc/yzen-script.js
Version Parameters
rss-for-yandex-zen/inc/yzen-script.js?ver=1.28

HTML / DOM Fingerprints

HTML Comments
<!-- rss-for-yandex-zen -->
Data Attributes
data-yzen-nonce
JS Globals
yzen_options
FAQ

Frequently Asked Questions about RSS for Yandex Zen