
RSS Via Shortcode for Page & Post Security & Risk Analysis
wordpress.org/plugins/rss-via-shortcode-on-page-postDonate link: http://susantaslab.com/ Tags: rss, post, page, shortcode, rss to post, feed to post, auto blogging, App, atom, atom feed, atom reader, f …
Is RSS Via Shortcode for Page & Post Safe to Use in 2026?
Generally Safe
Score 85/100RSS Via Shortcode for Page & Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "rss-via-shortcode-on-page-post" v1.2.b exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the proper escaping of all outputs are strong indicators of secure coding practices. Furthermore, the lack of file operations, external HTTP requests, and the complete absence of any recorded vulnerabilities in its history further bolster its security profile.
However, a significant concern arises from the complete lack of nonce checks and capability checks. While the current attack surface (limited to a single shortcode) is small and there are no unprotected entry points, this absence of authorization and integrity checks presents a potential risk. If the shortcode's functionality were to evolve or if new vulnerabilities were discovered in the future, the lack of these fundamental security mechanisms could make it easier for attackers to exploit the plugin. The plugin's small attack surface and clean code are positive, but the reliance on the absence of vulnerabilities rather than robust security controls is a weakness.
Key Concerns
- Missing nonce checks
- Missing capability checks
RSS Via Shortcode for Page & Post Security Vulnerabilities
RSS Via Shortcode for Page & Post Code Analysis
RSS Via Shortcode for Page & Post Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
RSS Via Shortcode for Page & Post Maintenance & Trust
Maintenance Signals
Community Trust
RSS Via Shortcode for Page & Post Alternatives
No alternatives data available yet.
RSS Via Shortcode for Page & Post Developer Profile
2 plugins · 240 total installs
How We Detect RSS Via Shortcode for Page & Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
rss-via-shortcode.php?ver=1.2.bHTML / DOM Fingerprints
rss_excerpt<ul><li><h3><a href="" target="" rel="external"></a></h3>