RSS only posts Security & Risk Analysis

wordpress.org/plugins/rss-only-posts

Join the secret RSS club (https://kevq.uk/rss-club/)! Engage with your most loyal readers by delivering them unique content that's only available …

0 active installs v0.2 PHP 7.4+ WP 5.8+ Updated Feb 3, 2022
feedrss
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is RSS only posts Safe to Use in 2026?

Generally Safe

Score 85/100

RSS only posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "rss-only-posts" v0.2 plugin exhibits a strong security posture based on the provided static analysis. There are no identified critical or high-severity code signals like dangerous functions, unescaped output, or file operations. The plugin also demonstrates good practice by using prepared statements for all its SQL queries and has a single capability check, indicating an effort to control access. The absence of any recorded vulnerabilities in its history further reinforces this positive assessment, suggesting a well-maintained and secure codebase.

While the lack of identified vulnerabilities and the use of secure coding practices are significant strengths, the analysis does highlight a concern regarding the attack surface. With zero AJAX handlers, REST API routes, shortcodes, or cron events, the plugin effectively has no exposed entry points for direct interaction or potential exploitation. This minimal attack surface, combined with the absence of taint flows and dangerous functions, suggests a very low risk of remote code execution or privilege escalation vulnerabilities stemming from code execution within the plugin itself.

In conclusion, the "rss-only-posts" v0.2 plugin appears to be a secure option. Its strengths lie in its robust use of prepared statements, absence of known vulnerabilities, and minimal attack surface. The provided data indicates diligent security practices, making it a low-risk plugin.

Vulnerabilities
None known

RSS only posts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

RSS only posts Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

RSS only posts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries
Attack Surface

RSS only posts Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actioninitrssonlypost.php:15
actionadmin_print_styles-edit.phprssonlypost.php:18
actionpre_get_postsrssonlypost.php:25
actionenqueue_block_editor_assetsrssonlypost.php:70
filtermanage_posts_columnsrssonlypost.php:141
actionmanage_post_posts_custom_columnrssonlypost.php:149
filtermanage_edit-post_sortable_columnsrssonlypost.php:159
actionpre_get_postsrssonlypost.php:165
actioninitrssonlypost.php:192
Maintenance & Trust

RSS only posts Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedFeb 3, 2022
PHP min version7.4
Downloads766

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

RSS only posts Developer Profile

latz

9 plugins · 2K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
587 days
View full developer profile
Detection Fingerprints

How We Detect RSS only posts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rss-only-posts/rssonlypost.css
Script Paths
/wp-content/plugins/rss-only-posts/rssonlypost.min.js
Version Parameters
rssonlypost.min.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-rssonlypost
JS Globals
wp.elementwp.blockswp.componentswp.editor
REST Endpoints
/wp-json/wp/v2/posts?meta=_rssonlypost
FAQ

Frequently Asked Questions about RSS only posts