
WP-Feedmail Security & Risk Analysis
wordpress.org/plugins/wp-feedmailIt displays a form in the widget area which allows to subscribe to Google Feedburner Directly. It also stores the subscribers list in the database.
Is WP-Feedmail Safe to Use in 2026?
Generally Safe
Score 85/100WP-Feedmail has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-feedmail plugin v1.1.1, based on the static analysis, exhibits a generally good security posture with several positive indicators. Notably, all SQL queries are prepared, which significantly mitigates the risk of SQL injection vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests also reduces the potential attack vectors. The plugin also demonstrates an effort towards security by including a capability check.
However, there are significant concerns regarding output sanitization and a lack of nonce checks. The very low percentage of properly escaped outputs (9%) suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as user-provided data is likely being rendered without adequate sanitization. The taint analysis revealing flows with unsanitized paths further corroborates this. The complete absence of nonce checks, especially if the shortcode can be influenced by user input, presents an open door for Cross-Site Request Forgery (CSRF) attacks. The vulnerability history being clean is a positive sign, but it does not negate the risks identified in the current code analysis. The limited attack surface is a strength, but the identified weaknesses within that surface are serious.
In conclusion, while wp-feedmail has made strides in areas like SQL query security, the critical shortcomings in output escaping and nonce verification expose it to significant XSS and CSRF risks. These issues, if exploited, could lead to serious compromise of user accounts and the WordPress site. The absence of past vulnerabilities should not lead to complacency, given the current code quality concerns.
Key Concerns
- Low percentage of properly escaped output
- Taint flows with unsanitized paths
- No nonce checks
WP-Feedmail Security Vulnerabilities
WP-Feedmail Release Timeline
WP-Feedmail Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP-Feedmail Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
WP-Feedmail Maintenance & Trust
Maintenance Signals
Community Trust
WP-Feedmail Alternatives
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
WP-Feedmail Developer Profile
2 plugins · 20 total installs
How We Detect WP-Feedmail
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-feedmail/css/wp-feedmail-style.css/wp-content/plugins/wp-feedmail/js/wp-feedmail-script.js/wp-content/plugins/wp-feedmail/js/wp-feedmail-script.jswp-feedmail/css/wp-feedmail-style.css?ver=wp-feedmail/js/wp-feedmail-script.js?ver=HTML / DOM Fingerprints
feedmail-formid="feedmail_addsub"id="response1"id="response2"<div class="feedmail-form"><p><form name="feedmail_addsub" id="feedmail_addsub" method="post"<input name="fsub_name" type="text" placeholder="Name">