
RSS Feed Retriever Security & Risk Analysis
wordpress.org/plugins/wp-rss-retrieverThe fastest RSS feeds plugin for WordPress. Includes excerpt & thumbnail image. Use as a news aggregator, autoblog, or RSS parsing.
Is RSS Feed Retriever Safe to Use in 2026?
Mostly Safe
Score 84/100RSS Feed Retriever is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The wp-rss-retriever plugin v1.6.10 exhibits a generally positive security posture based on the static analysis. The absence of critical or high severity taint flows, along with the use of prepared statements for all SQL queries, are strong indicators of secure coding practices. Furthermore, the plugin correctly implements nonce checks and capability checks for its entry points, and it does not appear to bundle any external libraries, which can often be a source of vulnerabilities.
However, the plugin is not without its risks. The historical vulnerability data reveals two past medium severity CVEs, specifically related to Cross-Site Request Forgery (CSRF) and Missing Authorization. While currently none are unpatched, this history suggests a pattern where authentication and authorization mechanisms may have been previously inadequate. The static analysis shows a total of three entry points (AJAX handlers and shortcodes), all of which are reported as protected. Despite this, the historical vulnerability types warrant a cautious approach, as previously identified weaknesses in authorization could potentially be re-introduced or remain subtly present.
In conclusion, wp-rss-retriever v1.6.10 demonstrates good security practices in its current code, particularly in SQL handling and input validation for its identified entry points. The lack of critical static analysis findings is encouraging. Nevertheless, the history of medium severity vulnerabilities in CSRF and missing authorization necessitates ongoing vigilance and thorough auditing of any future updates to ensure these past issues are not re-emerging in less obvious ways.
Key Concerns
- Past medium severity CVEs (2)
RSS Feed Retriever Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WordPress RSS Feed Retriever <= 1.6.7 - Cross-Site Request Forgery
WordPress RSS Feed Retriever <= 1.6.7 - Missing Authorization
RSS Feed Retriever Code Analysis
SQL Query Safety
Output Escaping
RSS Feed Retriever Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
RSS Feed Retriever Maintenance & Trust
Maintenance Signals
Community Trust
RSS Feed Retriever Alternatives
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging
wp-rss-aggregator
The #1 WordPress RSS aggregator to quickly import RSS feeds, build a news aggregator, and for easy autoblogging.
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator
feedzy-rss-feeds
The most powerful WordPress RSS aggregator, helping you curate content, autoblog, import RSS & display unlimited RSS feeds within a few minutes.
Content Pilot – Autoblogging & Affiliate Marketing Suite
wp-content-pilot
Automatically post contents, create news feeds, import and display unlimited RSS feeds from various sources in a few clicks!
RSS Feeds News Blocks
rss-feed-news-blocks-free
Show RSS Feed on your posts and pages with shortcode to show and display single and multiple RSS feeds blocks like Popurls, Alltop, Netvibes.
WP Autoblog
wp-autoblog
WP Autoblog lets you import content from various sources. Import posts from multiple sources to fill your blog with content! Custom content filter: …
RSS Feed Retriever Developer Profile
2 plugins · 11K total installs
How We Detect RSS Feed Retriever
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-rss-retriever/inc/css/rss-retriever.csswp-rss-retriever/inc/css/rss-retriever.css?ver=HTML / DOM Fingerprints
data-rss-retriever-idwp_rss_retriever_params<div class="wp-rss-retriever"><div class="wp-rss-retriever-source">