
SB RSS feed plus Security & Risk Analysis
wordpress.org/plugins/sb-rss-feed-plusThis plugin will add post thumbnail to RSS feed items. Add signatur or simple ads. Create fulltext RSS (via special url).
Is SB RSS feed plus Safe to Use in 2026?
Generally Safe
Score 85/100SB RSS feed plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'sb-rss-feed-plus' v1.4.20 exhibits a generally positive security posture based on the provided static analysis. There are no identified attack vectors such as AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed without authentication or permission checks. Furthermore, the code does not utilize dangerous functions, perform file operations, make external HTTP requests, or contain any identified taint flows. The consistent use of prepared statements for SQL queries is a strong indicator of good security practices in database interactions.
However, there are some areas of concern that slightly detract from an otherwise strong profile. The most significant is the low percentage of properly escaped output (28%). This suggests a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed. The absence of nonce checks across any entry points, while seemingly minor given the lack of entry points, means that if any were introduced in the future without proper security, they would be unprotected. The vulnerability history being completely clear is a positive sign, indicating a lack of previously exploited or discovered security flaws, which is reassuring for the plugin's overall stability.
In conclusion, 'sb-rss-feed-plus' v1.4.20 demonstrates good foundational security with no critical or high-risk technical vulnerabilities identified in the static analysis and a clean vulnerability history. The primary weakness lies in the insufficient output escaping, which, if exploited, could lead to XSS issues. The lack of nonce checks also presents a minor potential risk should the attack surface expand. Despite these points, the plugin appears to be relatively secure, with the main recommendation being to improve output escaping practices.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks on any entry points
SB RSS feed plus Security Vulnerabilities
SB RSS feed plus Code Analysis
Output Escaping
SB RSS feed plus Attack Surface
WordPress Hooks 14
Maintenance & Trust
SB RSS feed plus Maintenance & Trust
Maintenance Signals
Community Trust
SB RSS feed plus Alternatives
Add Featured Image to RSS Feed
add-featured-image-to-rss-feed
Adds the featured image attached to posts to the beginning of the post content and excerpt in RSS feeds.
JMS Rss Feed
jms-rss-feed
Add the featured image tag in your posts RSS feed. For standard RSS feed XML, there is no image tag definition. This plugin will show the post featur …
Send Images to RSS
send-images-rss
Improve your RSS: for full text feeds, replace large site images with email friendly images. Customize summaries with images and beautiful excerpts.
Featured Image in RSS Feed by MailerLite
mailerlite-featured-image-in-rss-feed
This plugin automatically adds featured images of your posts into the RSS feed.
Feed Post Thumbnail
wp-feed-post-thumbnail
Adds MRSS namespace to the feed and uses post-thumbnail as media element in the feed. Settings available under Settings -> Reading.
SB RSS feed plus Developer Profile
4 plugins · 1K total installs
How We Detect SB RSS feed plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sb-rss-feed-plus/wp-settings-framework.php/wp-content/plugins/sb-rss-feed-plus/settings/sbrssfeed-cfg.php/wp-content/plugins/sb-rss-feed-plus/sb-rss-feed-plus.phpsb-rss-feed-plus.php?ver=wp-settings-framework.php?ver=HTML / DOM Fingerprints
<!-- If You like this plugin, please donate and support development. Thank You :) -->name="sbrssfeedcfg_settings[sbrssfeedcfg_info_version]"id="sbrssfeedcfg_info_version"name="cmd"name="encrypted"