
rss-per-page Security & Risk Analysis
wordpress.org/plugins/rss-per-pageThis plugin implements an widget which can show a different, page controled, rss feed.
Is rss-per-page Safe to Use in 2026?
Generally Safe
Score 85/100rss-per-page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'rss-per-page' plugin v1.6 presents a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries with prepared statements and includes a nonce check and capability check, suggesting some awareness of security principles. Its vulnerability history is clear, with no known CVEs, which is encouraging. However, the static analysis reveals critical concerns. The presence of `create_function` is a significant risk, as it can lead to code injection vulnerabilities if not handled with extreme care, and this function is considered deprecated and unsafe. Furthermore, a low rate of output escaping (17%) is a major red flag, indicating a high likelihood of cross-site scripting (XSS) vulnerabilities where user-supplied data is displayed without proper sanitization.
While the plugin has a small attack surface and no recorded vulnerabilities, the identified code signals and the lack of comprehensive output escaping create a notable risk. The use of `create_function` is a specific and severe weakness that could be exploited. The low output escaping rate means that many points of user interaction within the plugin could potentially lead to XSS. In conclusion, despite a clean vulnerability history and some good security implementations, the presence of `create_function` and widespread unescaped output significantly lower its overall security rating, making it a moderate to high-risk plugin.
Key Concerns
- Use of dangerous function create_function
- Low output escaping rate (17%)
rss-per-page Security Vulnerabilities
rss-per-page Code Analysis
Dangerous Functions Found
Output Escaping
rss-per-page Attack Surface
WordPress Hooks 6
Maintenance & Trust
rss-per-page Maintenance & Trust
Maintenance Signals
Community Trust
rss-per-page Alternatives
Super RSS Reader – Add attractive RSS Feed Widget
super-rss-reader
Display any RSS feed(s) in widget with news ticker effect in multiple tabs, thumbnails, customizable color themes and more.
RSS Feed Widget
rss-feed-widget
RSS Feed Widget with customizable slider. Feed title, description, image, censorship and a few other features which you can use.
Admin Dashboard RSS Feed
admin-dashboard-rss-feed
Admin Dashboard RSS Feed displays company news in the WordPress Admin Dashboard using an RSS feed. It provides quick access to the latest updates.
Category Country Aware WordPress
category-country-aware
Make both your post content and sidebar category and/or visitor location relevant.
RSS Blogroll
rss-blogroll
Sidebar widget that links to recent entries from RSS/Atom feeds.
rss-per-page Developer Profile
7 plugins · 50 total installs
How We Detect rss-per-page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rss-per-page/css/rss-per-page.cssrss-per-page/css/rss-per-page.css?ver=HTML / DOM Fingerprints
rss_per_page_hookwp_widget_plugin_boxwidget-texttitledatenonewsid="RSSID"name="rss_id"