All in one Social Feeds Security & Risk Analysis

wordpress.org/plugins/all-in-one-social-feeds

This plugin helps to display latest feeds from facebook, twitter,instagram, pinterest and youtube with tabs using a widget.

20 active installs v1.0.0 PHP + WP 3.5.0+ Updated Unknown
facebook-feedinstagram-feedpintrest-feedtwitter-feedyoutube-feed
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is All in one Social Feeds Safe to Use in 2026?

Generally Safe

Score 100/100

All in one Social Feeds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "all-in-one-social-feeds" v1.0.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and showing no known vulnerabilities (CVEs) to date. This suggests a developer who is aware of common pitfalls and has a history of writing secure code. However, several concerning aspects require attention. A significant portion of output (42%) is not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is echoed without sanitization. Furthermore, the taint analysis revealed one flow with unsanitized paths, which, while not classified as critical or high severity in this instance, indicates a potential weakness where user input could be manipulated to affect file system operations or other sensitive actions. The absence of nonce checks and capability checks, coupled with no apparent authentication checks on potential entry points (though the attack surface appears minimal in this version), also presents an indirect risk, as it relies heavily on the limited attack surface to prevent exploitation. The external HTTP requests are also a point to monitor for potential vulnerabilities if the external endpoints are compromised or introduce malicious content.

Key Concerns

  • High percentage of unescaped output
  • Taint flow with unsanitized path
  • No nonce checks implemented
  • No capability checks implemented
  • External HTTP requests made
Vulnerabilities
None known

All in one Social Feeds Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

All in one Social Feeds Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
34 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

58% escaped59 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<aiosf-page-setting> (pages\aiosf-page-setting.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

All in one Social Feeds Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuall-in-one-social-feeds.php:26
actionwidgets_initall-in-one-social-feeds.php:28
actionwp_enqueue_scriptsall-in-one-social-feeds.php:51
actionadmin_initall-in-one-social-feeds.php:59
Maintenance & Trust

All in one Social Feeds Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedUnknown
PHP min version
Downloads5K

Community Trust

Rating80/100
Number of ratings2
Active installs20
Developer Profile

All in one Social Feeds Developer Profile

Cynob IT Consultancy

9 plugins · 530 total installs

81
trust score
Avg Security Score
82/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect All in one Social Feeds

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/all-in-one-social-feeds/includes/front-style.css/wp-content/plugins/all-in-one-social-feeds/includes/js/scroller/jquery.mCustomScrollbar.concat.min.js/wp-content/plugins/all-in-one-social-feeds/includes/js/scroller/jquery.mCustomScrollbar.css/wp-content/plugins/all-in-one-social-feeds/includes/js/init.js/wp-content/plugins/all-in-one-social-feeds/includes/js/popup2.2.js/wp-content/plugins/all-in-one-social-feeds/includes/admin-style.css
Script Paths
includes/js/scroller/jquery.mCustomScrollbar.concat.min.jsincludes/js/init.jsincludes/js/popup2.2.js

HTML / DOM Fingerprints

JS Globals
AIOSF_URL
FAQ

Frequently Asked Questions about All in one Social Feeds