YD FeedWordPress Content Filter Security & Risk Analysis

wordpress.org/plugins/yd-feedwordpress-content-filter

This plugin is an add-on to the FeedWordPress RSS content syndication plugin.

10 active installs v0.2.0 PHP + WP 2.8+ Updated Nov 24, 2010
automaticenglishimagepostposts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is YD FeedWordPress Content Filter Safe to Use in 2026?

Generally Safe

Score 85/100

YD FeedWordPress Content Filter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The "yd-feedwordpress-content-filter" plugin version 0.2.0 exhibits a generally good security posture with no known vulnerabilities and a clean vulnerability history. The static analysis shows a small attack surface with no unprotected entry points, no dangerous functions, and all SQL queries using prepared statements. The presence of nonce and capability checks further enhances security.

However, there are some areas of concern. A significant portion of output (95%) is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if malicious data is processed and displayed without proper sanitization. Additionally, one taint flow with an unsanitized path indicates a potential for information disclosure or path traversal, though its severity is not specified as critical or high. The plugin also performs file operations which, combined with the unsanitized path, warrants careful review.

In conclusion, while the plugin avoids common pitfalls like raw SQL or unauthenticated entry points, the high rate of unescaped output and the identified unsanitized path are significant weaknesses that could be exploited. The absence of past vulnerabilities is positive, but the current code signals suggest potential risks that should be addressed.

Key Concerns

  • High rate of unescaped output
  • Taint flow with unsanitized path
  • File operations present
Vulnerabilities
None known

YD FeedWordPress Content Filter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

YD FeedWordPress Content Filter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
54
3 escaped
Nonce Checks
1
Capability Checks
1
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

5% escaped57 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
form_footer (inc\yd-widget-framework.inc.php:534)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

YD FeedWordPress Content Filter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuinc\yd-widget-framework.inc.php:84
actionwidgets_initinc\yd-widget-framework.inc.php:85
actionwp_print_stylesinc\yd-widget-framework.inc.php:87
actionplugins_loadedinc\yd-widget-framework.inc.php:88
actionwp_footerinc\yd-widget-framework.inc.php:89
actionsyndicated_postyd-feedwordpress-content-filter.php:123
actionpost_syndicated_itemyd-feedwordpress-content-filter.php:125
actionupdate_syndicated_itemyd-feedwordpress-content-filter.php:126

Scheduled Events 2

yd_hourly_event
yd_daily_event
Maintenance & Trust

YD FeedWordPress Content Filter Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedNov 24, 2010
PHP min version
Downloads19K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

YD FeedWordPress Content Filter Developer Profile

Yann at WP&Co

14 plugins · 180 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect YD FeedWordPress Content Filter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about YD FeedWordPress Content Filter