
WP News feed widget Security & Risk Analysis
wordpress.org/plugins/wp-news-feed-widgetA simple news feed widget with pagination
Is WP News feed widget Safe to Use in 2026?
Generally Safe
Score 85/100WP News feed widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-news-feed-widget" v1.2 plugin exhibits a generally good security posture, with no recorded vulnerabilities (CVEs) and a clean taint analysis. The plugin demonstrates best practices by exclusively using prepared statements for SQL queries and avoids external HTTP requests and file operations. The attack surface is small, consisting of only two AJAX handlers, and importantly, none of these entry points are immediately identified as unprotected based on the provided data.
However, there are areas for improvement. The presence of the `create_function` dangerous function, although only one instance, is a significant concern as it can lead to code injection vulnerabilities if not handled with extreme care and strict sanitization of its input. Furthermore, the output escaping rate is quite low at 28%. This suggests that a substantial portion of the plugin's output might be vulnerable to Cross-Site Scripting (XSS) attacks, especially if user-supplied data is directly reflected in the output without proper sanitization or escaping.
While the lack of historical vulnerabilities is a positive indicator, it doesn't completely negate the risks identified in the static analysis. The plugin's strengths lie in its secure database interactions and limited attack vectors. Its primary weaknesses are the use of a dangerous function and a concerningly low rate of output escaping, which could expose it to XSS vulnerabilities. Overall, the plugin is in a relatively secure state but requires immediate attention to address the identified code signals and improve output sanitization.
Key Concerns
- Dangerous function (create_function) detected
- Low output escaping rate (28%)
WP News feed widget Security Vulnerabilities
WP News feed widget Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WP News feed widget Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
WP News feed widget Maintenance & Trust
Maintenance Signals
Community Trust
WP News feed widget Alternatives
Mailjet Email Marketing
mailjet-for-wordpress
Includes WooCommerce automated and order emails. Design, send and track engaging marketing and transactional emails from your WordPress admin.
WP News and Scrolling Widgets
sp-news-and-widget
A quick, easy way to add an News custom post type, News widget, vertical scrolling news widget to WordPress. Also work with Gutenberg shortcode block.
Super RSS Reader – Add attractive RSS Feed Widget
super-rss-reader
Display any RSS feed(s) in widget with news ticker effect in multiple tabs, thumbnails, customizable color themes and more.
WP Latest Posts
wp-latest-posts
Load your content from posts, page, tags or custom post type and display it anywhere in WordPress including in Gutenberg editor
WP Subscribe
wp-subscribe
WP Subscribe is a simple but powerful subscription plugin which supports MailChimp, Aweber and Feedburner.
WP News feed widget Developer Profile
4 plugins · 2.0M total installs
How We Detect WP News feed widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-news-feed-widget/css/light.css/wp-content/plugins/wp-news-feed-widget/css/dark.css/wp-content/plugins/wp-news-feed-widget/js/wp-newsfw.min.jswp-news-feed-widget/js/wp-newsfw.min.js?ver=HTML / DOM Fingerprints
wp-news-feed-widgetwp-newsfw-itemwpnewsfw