Rss slider on post Security & Risk Analysis

wordpress.org/plugins/rss-slider-on-post

Rss slider on post plugin create the scroller/slider text gallery into the posts and pages, that makes rss integration to your web site very easy.

100 active installs v8.3 PHP + WP 3.2+ Updated Oct 29, 2023
feedrssslider
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Rss slider on post Safe to Use in 2026?

Generally Safe

Score 85/100

Rss slider on post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "rss-slider-on-post" v8.3 plugin exhibits a generally good security posture, with no known vulnerabilities recorded and a significant effort towards secure coding practices. The static analysis reveals a limited attack surface consisting of a single shortcode, with no unprotected entry points. Importantly, the plugin correctly utilizes prepared statements for all SQL queries, mitigating the risk of SQL injection. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests are positive indicators. However, a concerning weakness lies in the output escaping. With only 45% of outputs properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis did not uncover immediate issues, the lack of robust output escaping means that even a minor oversight in sanitizing user-supplied data before output could lead to an exploit. The plugin also lacks capability checks for its shortcode, which could potentially be a vector for privilege escalation if the shortcode's functionality is sensitive and can be triggered by unauthenticated users, though the limited attack surface suggests this risk is currently contained. The vulnerability history being empty is a strong positive, indicating a responsible development history. Overall, the plugin is well-constructed in many areas but requires immediate attention to its output escaping to address potential XSS risks.

Key Concerns

  • Insufficient output escaping
  • Lack of capability checks on shortcode
Vulnerabilities
None known

Rss slider on post Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Rss slider on post Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
14 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

45% escaped31 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
rssslider_admin_options (rss-slider-on-post.php:40)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Rss slider on post Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[rss-slider-on-post] rss-slider-on-post.php:429
WordPress Hooks 3
actionplugins_loadedrss-slider-on-post.php:428
actionadmin_menurss-slider-on-post.php:432
actionwp_enqueue_scriptsrss-slider-on-post.php:433
Maintenance & Trust

Rss slider on post Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedOct 29, 2023
PHP min version
Downloads21K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

Rss slider on post Developer Profile

gopi_plus

8 plugins · 1K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
1046 days
View full developer profile
Detection Fingerprints

How We Detect Rss slider on post

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rss-slider-on-post/rss-slider-on-post.js
Script Paths
/rss-slider-on-post/rss-slider-on-post.js

HTML / DOM Fingerprints

CSS Classes
wrapform-wrapicon32icon32-posts-post
Data Attributes
name="rssslider_form"action=""name="rss_s1"id="rss_s1"name="rssslider_height_1"id="rssslider_height_1"+28 more
FAQ

Frequently Asked Questions about Rss slider on post