
BVD Easy Social Feeds & Images Security & Risk Analysis
wordpress.org/plugins/bvd-easy-social-feeds-imagesA WordPress plugin to display any public Facebook, Twitter, or Instagram feed on your website.
Is BVD Easy Social Feeds & Images Safe to Use in 2026?
Generally Safe
Score 85/100BVD Easy Social Feeds & Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bvd-easy-social-feeds-images plugin, version 1.0.7, exhibits a mixed security posture. On the positive side, it demonstrates good practices by not having any known CVEs and utilizes prepared statements for all its SQL queries, indicating a resistance to SQL injection vulnerabilities. It also has no reported bundled libraries, reducing the risk of using outdated or vulnerable third-party code.
However, significant concerns arise from the static analysis. A substantial number of file operations (10) and external HTTP requests (2) exist, which can be potential attack vectors if not handled securely. Crucially, none of the 163 observed output operations are properly escaped, posing a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the absence of nonce checks and capability checks across all entry points, including the 3 shortcodes, makes the plugin vulnerable to CSRF attacks and unauthorized actions.
The taint analysis reveals 6 flows with unsanitized paths, which, while not classified as critical or high severity by the analysis, still represent a potential risk for path traversal or unintended file access. The plugin's vulnerability history being entirely clear is a positive sign, but it doesn't negate the immediate risks identified in the static and taint analyses. In conclusion, while the plugin avoids common database and known vulnerability issues, its lack of output escaping and insufficient authorization checks on its entry points present considerable security weaknesses that require immediate attention.
Key Concerns
- All output operations are unescaped
- No nonce checks present
- No capability checks present
- Taint flows with unsanitized paths (6)
- Numerous file operations (10)
- External HTTP requests (2)
BVD Easy Social Feeds & Images Security Vulnerabilities
BVD Easy Social Feeds & Images Release Timeline
BVD Easy Social Feeds & Images Code Analysis
Output Escaping
Data Flow Analysis
BVD Easy Social Feeds & Images Attack Surface
Shortcodes 3
WordPress Hooks 5
Maintenance & Trust
BVD Easy Social Feeds & Images Maintenance & Trust
Maintenance Signals
Community Trust
BVD Easy Social Feeds & Images Alternatives
Civic Social Feeds
civic-social-feeds
This plugin provides Wordpress administrators a configuration page to set up credentials for various social networks in order to access API’s and gets …
Tagembed Social Feeds Widget
tagembed-widget
Collect & Embed Instagram Feed, Embed Facebook Feed, Embed YouTube Videos, Embed Twitter Feed, Google Reviews & 15+ Social Media Feed on website.
Curator.io
curatorio
Aggregate and embed your social media posts on your site (Facebook, Twitter, Instagram, Pinterest and many more) as a beautiful social media feed.
Gleam: Run Competitions on Your WordPress Blog
gleam
An amazing solution to run competitions on your blog using combinations of social actions.
Wp Fixed Social Profile Icons
wp-fixed-social-profile-icons
Fixed Social Icons for your wordpress website
BVD Easy Social Feeds & Images Developer Profile
1 plugin · 10 total installs
How We Detect BVD Easy Social Feeds & Images
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bvd-easy-social-feeds-images/bvd-social-feeds-user-style.cssbvd-social-feeds-user-style.css?ver=HTML / DOM Fingerprints
data-bvd-social-feedBVD_SOCIAL_FEEDS_INSTAGRAM_LOADERBVD_SOCIAL_FEEDS_INSTAGRAM_GRID[bvd-instagram-feed][bvd-facebook-feed][bvd-twitter-feed]