
YD FeedWordPress Content Filter Security & Risk Analysis
wordpress.org/plugins/yd-feedwordpress-content-filterThis plugin is an add-on to the FeedWordPress RSS content syndication plugin.
Is YD FeedWordPress Content Filter Safe to Use in 2026?
Generally Safe
Score 85/100YD FeedWordPress Content Filter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "yd-feedwordpress-content-filter" plugin version 0.2.0 exhibits a generally good security posture with no known vulnerabilities and a clean vulnerability history. The static analysis shows a small attack surface with no unprotected entry points, no dangerous functions, and all SQL queries using prepared statements. The presence of nonce and capability checks further enhances security.
However, there are some areas of concern. A significant portion of output (95%) is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if malicious data is processed and displayed without proper sanitization. Additionally, one taint flow with an unsanitized path indicates a potential for information disclosure or path traversal, though its severity is not specified as critical or high. The plugin also performs file operations which, combined with the unsanitized path, warrants careful review.
In conclusion, while the plugin avoids common pitfalls like raw SQL or unauthenticated entry points, the high rate of unescaped output and the identified unsanitized path are significant weaknesses that could be exploited. The absence of past vulnerabilities is positive, but the current code signals suggest potential risks that should be addressed.
Key Concerns
- High rate of unescaped output
- Taint flow with unsanitized path
- File operations present
YD FeedWordPress Content Filter Security Vulnerabilities
YD FeedWordPress Content Filter Code Analysis
Output Escaping
Data Flow Analysis
YD FeedWordPress Content Filter Attack Surface
WordPress Hooks 8
Scheduled Events 2
Maintenance & Trust
YD FeedWordPress Content Filter Maintenance & Trust
Maintenance Signals
Community Trust
YD FeedWordPress Content Filter Alternatives
YD Recent Images
yd-recent-images
Recent images in a Widget
Chip Get Image
chip-get-image
A flexible image script for adding thumbnails and feature images to the post.
Gif Controller
gif-controller
The GIF Controller is a simple and lightweight plugin for playing and stopping the GIF images.
Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories
post-expirator
PublishPress Future can make scheduled changes to your content. You can unpublish posts, move posts to a new status, update the categories, and more.
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
YD FeedWordPress Content Filter Developer Profile
14 plugins · 180 total installs
How We Detect YD FeedWordPress Content Filter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.