AtticThemes: Social Feed Security & Risk Analysis

wordpress.org/plugins/atticthemes-social-feed

Display posts from your Instagram or Dribbble account in your blog posts, pages or any shortcode enabled area.

10 active installs v1.0.1 PHP + WP 4.0.0+ Updated Oct 4, 2016
dribbblefeedinstagramsocialwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AtticThemes: Social Feed Safe to Use in 2026?

Generally Safe

Score 85/100

AtticThemes: Social Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The atticthemes-social-feed plugin version 1.0.1 presents a generally strong security posture, with no known vulnerabilities or critical code signals like dangerous functions or unsanitized taint flows. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce checks. However, there are areas for improvement. The low percentage of properly escaped output (57%) is a notable concern, as it could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered without sufficient sanitization. The plugin also makes an external HTTP request, which, while not inherently insecure, warrants careful review to ensure the target is trustworthy and the request is handled securely. The lack of recorded vulnerability history is positive, suggesting consistent security focus by the developers, but the limited output escaping is a weakness that should be addressed.

Key Concerns

  • Low output escaping percentage
  • External HTTP request
Vulnerabilities
None known

AtticThemes: Social Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AtticThemes: Social Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
28
37 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

57% escaped65 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
render_admin (includes\dribbble\class.php:423)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AtticThemes: Social Feed Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[atsf_dribbble] includes\dribbble\class.php:511
[atsf_instagram] includes\instagram\class.php:501
WordPress Hooks 7
actioninitatticthemes-social-feed.php:119
actionadmin_enqueue_scriptsatticthemes-social-feed.php:124
actionwp_enqueue_scriptsatticthemes-social-feed.php:129
actionadmin_menuincludes\dribbble\class.php:505
actionwidgets_initincludes\dribbble\class.php:524
actionadmin_menuincludes\instagram\class.php:495
actionwidgets_initincludes\instagram\class.php:514
Maintenance & Trust

AtticThemes: Social Feed Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedOct 4, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

AtticThemes: Social Feed Developer Profile

AtticThemes

3 plugins · 90 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AtticThemes: Social Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/atticthemes-social-feed/resources/css/admin.css/wp-content/plugins/atticthemes-social-feed/resources/css/style.css
Version Parameters
atticthemes-social-feed/resources/css/admin.css?ver=atticthemes-social-feed/resources/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
attic-social-feed
HTML Comments
<!-- AtticThemes -->
Data Attributes
data-tokendata-type
Shortcode Output
[attic_social_feed[attic_social_feed_dribbble[attic_social_feed_instagram
FAQ

Frequently Asked Questions about AtticThemes: Social Feed