RSS Just Better Security & Risk Analysis

wordpress.org/plugins/rss-just-better

Displays a list of RSS/Atom feed items given the feed URL and other parameters (optionals). Highly customizable.

400 active installs v1.4 PHP + WP 2.8+ Updated Nov 19, 2015
atomfeedfeedsrss
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RSS Just Better Safe to Use in 2026?

Generally Safe

Score 85/100

RSS Just Better has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "rss-just-better" v1.4 plugin exhibits a generally good security posture, primarily due to the absence of known vulnerabilities and a lack of critical code signals in the static analysis. The absence of raw SQL queries, file operations, external HTTP requests, and the use of prepared statements for the few SQL queries detected are all positive indicators. Furthermore, the plugin boasts a very small attack surface with no unprotected entry points identified.

However, there are significant concerns regarding output escaping, with only 4% of outputs being properly escaped. This is a substantial weakness that could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled correctly before being displayed. The lack of nonce checks and capability checks on the identified entry points, while not immediately resulting in a critical score due to the limited attack surface, represent missed opportunities for robust security, especially if the plugin's functionality were to expand.

Given the plugin's history of zero known CVEs and no recorded vulnerabilities, it suggests a developer who has either been diligent or has not yet encountered exploitable flaws. The strengths lie in its minimal attack surface and good database practices. The primary weakness is the poor output escaping, which requires immediate attention. Overall, while the plugin is not overtly dangerous in its current state, the output escaping issue makes it susceptible to certain types of attacks and warrants caution.

Key Concerns

  • Poor output escaping
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

RSS Just Better Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

RSS Just Better Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
80
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

4% escaped83 total outputs
Attack Surface

RSS Just Better Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[RSSjb] RSS-just-better.php:784
WordPress Hooks 1
actionwidgets_initRSS-just-better.php:75
Maintenance & Trust

RSS Just Better Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedNov 19, 2015
PHP min version
Downloads46K

Community Trust

Rating90/100
Number of ratings8
Active installs400
Developer Profile

RSS Just Better Developer Profile

Stefi

2 plugins · 410 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RSS Just Better

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rss-just-better/rss-cube.gif

HTML / DOM Fingerprints

CSS Classes
rssjustbetter
Data Attributes
id="rss-just-better"data-widget_type="rss-just-better"data-action="register_widget"
FAQ

Frequently Asked Questions about RSS Just Better