
RSS Includes Pages Security & Risk Analysis
wordpress.org/plugins/rss-includes-pagesModifies RSS feeds so that they include pages and not just posts.
Is RSS Includes Pages Safe to Use in 2026?
Generally Safe
Score 100/100RSS Includes Pages has a strong security track record. Known vulnerabilities have been patched promptly.
The 'rss-includes-pages' plugin v3.8 presents a mixed security posture. On the positive side, the static analysis reveals no identifiable attack surface through common entry points like AJAX, REST API, shortcodes, or cron events. Furthermore, the code signals indicate no dangerous functions, file operations, external HTTP requests, or bundled libraries that could pose immediate risks. Taint analysis also shows no critical or high severity flows with unsanitized paths.
However, there are notable concerns. The plugin has a history of vulnerabilities, specifically a medium severity Cross-Site Scripting (XSS) flaw recorded in 2017. While this vulnerability is listed as currently unpatched, it's important to note the absence of any recent vulnerabilities suggests that the specific XSS issue might have been fixed in later versions, or that the plugin has not been actively targeted or found to be vulnerable since then. A significant concern lies in the SQL queries, where 100% of the two identified queries are not using prepared statements. This leaves the plugin susceptible to SQL injection vulnerabilities, especially if any of the input influencing these queries is not strictly sanitized. The output escaping is also only 60% properly escaped, which could lead to XSS if user-supplied data is echoed without adequate sanitization.
In conclusion, while the plugin has a minimal attack surface and no critical code signals, the presence of past vulnerabilities and, more importantly, the lack of prepared statements for all SQL queries and incomplete output escaping represent significant risks. The fact that the single historical vulnerability is marked as unpatched is a major red flag. Users should exercise caution and consider updating to a later version if available, or carefully audit the plugin's usage to mitigate potential SQL injection and XSS risks.
Key Concerns
- Raw SQL queries without prepared statements
- Output escaping only 60% properly escaped
- Known unpatched medium severity CVE
RSS Includes Pages Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
RSS Includes Pages <= 3.6 - Cross-Site Scripting
RSS Includes Pages Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
RSS Includes Pages Attack Surface
WordPress Hooks 9
Maintenance & Trust
RSS Includes Pages Maintenance & Trust
Maintenance Signals
Community Trust
RSS Includes Pages Alternatives
Disable Feeds
disable-feeds
Disables all RSS/Atom/RDF feeds on your WordPress site.
GN Publisher: Google News Compatible RSS Feeds
gn-publisher
GN Publisher makes RSS feeds that comply with the Google News RSS Feed Technical Requirements for including your site in the Google News.
Disable Feeds WP
disable-feeds-wp
Disables all RSS/Atom/RDF feeds on your WordPress site.
RSS Redirect & Feedburner Alternative
feedburner-alternative-and-rss-redirect
Free Feedburner Alternative and RSS Redirect plugin from follow.it.
Disable Feeds and Comments
disable-rss-feeds-and-comments
This WordPress plugin, "Disable RSS Feeds and Comments," gives you the ability to turn off both the RSS feeds and comments on pages and/or p …
RSS Includes Pages Developer Profile
7 plugins · 195K total installs
How We Detect RSS Includes Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/rss-includes-pages/css/rssip.cssHTML / DOM Fingerprints
side-labeltextbox-longdisabled='disabled'