
SuperRSS by Leo Balter Security & Risk Analysis
wordpress.org/plugins/superrssTotally in Portuguese-Br yet, this add a very customizabole rss or atom feed. Made after the standard wp rss plugin.
Is SuperRSS by Leo Balter Safe to Use in 2026?
Generally Safe
Score 85/100SuperRSS by Leo Balter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'superrss' plugin, version 1.0, presents a mixed security profile. On the positive side, it demonstrates good practices by having zero known CVEs and no recorded vulnerabilities in its history. Furthermore, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, significantly reducing common attack vectors. The plugin also avoids bundled libraries, which can sometimes introduce outdated or vulnerable code.
However, several areas raise concerns. The presence of the `create_function` is a significant red flag, as it can be exploited for code injection. While the total attack surface appears small with zero identified entry points, this analysis might be incomplete without a full audit. A critical issue is the low percentage of properly escaped output (29%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data is displayed back to the user without proper sanitization. The absence of nonce checks on any potential entry points and the single capability check also suggest a potentially weak authorization mechanism if any hidden entry points exist.
In conclusion, while the lack of known vulnerabilities and the secure handling of SQL are strengths, the reliance on `create_function` and the widespread unescaped output are serious weaknesses that could expose users to XSS and potential code execution attacks. This plugin requires immediate attention to address these critical security flaws.
Key Concerns
- Use of dangerous function create_function
- Low percentage of properly escaped output
- No nonce checks on potential entry points
- Limited capability checks
SuperRSS by Leo Balter Security Vulnerabilities
SuperRSS by Leo Balter Code Analysis
Dangerous Functions Found
Output Escaping
SuperRSS by Leo Balter Attack Surface
WordPress Hooks 1
Maintenance & Trust
SuperRSS by Leo Balter Maintenance & Trust
Maintenance Signals
Community Trust
SuperRSS by Leo Balter Alternatives
Disable Feeds
disable-feeds
Disables all RSS/Atom/RDF feeds on your WordPress site.
Disable Feeds WP
disable-feeds-wp
Disables all RSS/Atom/RDF feeds on your WordPress site.
FeedWordPress
feedwordpress
FeedWordPress syndicates content from feeds you choose into your WordPress weblog.
RSS Just Better
rss-just-better
Displays a list of RSS/Atom feed items given the feed URL and other parameters (optionals). Highly customizable.
Feed Template Customize
feed-template-customize
This plugin modifies RSS feeds and ATOM feeds as you want.
SuperRSS by Leo Balter Developer Profile
1 plugin · 10 total installs
How We Detect SuperRSS by Leo Balter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/superrss/widget.cssHTML / DOM Fingerprints
rssSummaryrss-datewidget-superrss