Sexy RSS Footer Security & Risk Analysis

wordpress.org/plugins/sexy-rss-footer

Sexy RSS Footer enables you to add any possible content at the end of every feed entry. This includes variables like number of comments, author etc.

10 active installs v0.1 PHP + WP 2.8+ Updated Jun 2, 2011
commentsfeedflattrfooterrss
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sexy RSS Footer Safe to Use in 2026?

Generally Safe

Score 85/100

Sexy RSS Footer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The "sexy-rss-footer" plugin v0.1 exhibits a generally strong security posture based on the provided static analysis. The absence of known vulnerabilities, CVEs, and the fact that all SQL queries utilize prepared statements are positive indicators. Furthermore, the plugin has a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. This indicates a good practice of limiting potential entry points and securing those that do exist. However, a significant concern arises from the output escaping results. With 3 total outputs and 0% properly escaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities. This means that data processed by the plugin and then displayed to users might not be sufficiently sanitized, allowing malicious scripts to be injected and executed within the user's browser. The vulnerability history being completely clear is a strength, but the critical flaw in output escaping suggests that the plugin's development practices may not consistently address all security best practices, despite its clean history.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Sexy RSS Footer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sexy RSS Footer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Sexy RSS Footer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menusexy-rss-footer.php:33
actionadmin_initsexy-rss-footer.php:76
filterthe_content_feedsexy-rss-footer.php:135
Maintenance & Trust

Sexy RSS Footer Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedJun 2, 2011
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Sexy RSS Footer Developer Profile

zhenech

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sexy RSS Footer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sexy-rss-footer/sexy-rss-footer.css/wp-content/plugins/sexy-rss-footer/sexy-rss-footer.js
Script Paths
/wp-content/plugins/sexy-rss-footer/sexy-rss-footer.js

HTML / DOM Fingerprints

CSS Classes
sexy-rss-footersrf_descriptionsrf_help_table
Data Attributes
title
Shortcode Output
<p class="sexy-rss-footer">
FAQ

Frequently Asked Questions about Sexy RSS Footer