
Social Feed for WordPress by CompyGo Security & Risk Analysis
wordpress.org/plugins/compygo-social-feedDisplay completely customizable Facebook Feed on your WordPress website. Also it supports Instagram photos and Youtube videos.
Is Social Feed for WordPress by CompyGo Safe to Use in 2026?
Generally Safe
Score 100/100Social Feed for WordPress by CompyGo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "compygo-social-feed" plugin v2.0.0 exhibits a concerning security posture due to a significantly exposed attack surface without adequate authentication. While the plugin demonstrates good practices in database interactions by using prepared statements for all SQL queries and properly escaping the vast majority of its output, these strengths are overshadowed by the sheer number of unprotected AJAX handlers.
Specifically, the analysis reveals 18 AJAX handlers, all of which lack authentication checks. This represents a critical vulnerability as it allows any unauthenticated user to trigger these handlers, potentially leading to unintended actions or information disclosure. While the plugin has no recorded vulnerability history and shows no critical taint flows, the lack of authorization on such a large portion of its entry points is a significant risk that cannot be ignored. The presence of nonce checks and capability checks on only a few functions further highlights this deficiency. The bundled Guzzle library, while not explicitly flagged as vulnerable in this report, is an area to monitor for potential outdated dependencies in future audits.
In conclusion, while the "compygo-social-feed" plugin has a clean vulnerability history and uses secure coding practices for SQL and output handling, the massive unprotected attack surface through AJAX is a critical weakness. This needs immediate remediation to prevent exploitation.
Key Concerns
- Unprotected AJAX handlers
- Large attack surface without auth
- Limited capability checks
Social Feed for WordPress by CompyGo Security Vulnerabilities
Social Feed for WordPress by CompyGo Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Social Feed for WordPress by CompyGo Attack Surface
AJAX Handlers 18
WordPress Hooks 14
Maintenance & Trust
Social Feed for WordPress by CompyGo Maintenance & Trust
Maintenance Signals
Community Trust
Social Feed for WordPress by CompyGo Alternatives
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress
custom-facebook-feed
Formerly "Custom Facebook Feed". Display completely customizable Facebook feeds of a Facebook page. Supports Facebook oEmbeds.
Mitsol Social Post Feed
facebook-wall-and-social-integration
Formerly known as Facebook wall and social integration allows you to display completely customizable Facebook feed of any public Facebook page or grou …
Mirror App – Social Page
mirror-app-social-page
Display your social page updates — including your full Facebook Feed with posts, photos, and videos — beautifully on your WordPress site using a simpl …
Easy Social Feed – Social Photos Gallery and Post Feed for WordPress
easy-facebook-likebox
Display Instagram, Facebook & YouTube feeds with photos, videos, reels, events & galleries. Fast, responsive & easy to set up.
Mongoose Page Plugin
facebook-page-feed-graph-api
The most popular way to display the Facebook Page Plugin on your WordPress website. Easy implementation using a shortcode or widget.
Social Feed for WordPress by CompyGo Developer Profile
1 plugin · 20 total installs
How We Detect Social Feed for WordPress by CompyGo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/compygo-social-feed/pub/frontend.css/wp-content/plugins/compygo-social-feed/pub/slick.css/wp-content/plugins/compygo-social-feed/pub/slick-theme.css/wp-content/plugins/compygo-social-feed/pub/frontend.main.js/wp-content/plugins/compygo-social-feed/pub/library/masonry.pkgd.min.js/wp-content/plugins/compygo-social-feed/pub/library/image-loader.min.js/wp-content/plugins/compygo-social-feed/pub/library/slick.min.jscompygo-social-feed/pub/frontend.css?ver=2.0.0compygo-social-feed/pub/slick.css?ver=2.0.0compygo-social-feed/pub/slick-theme.css?ver=2.0.0compygo-social-feed/pub/frontend.main.js?ver=2.0.0compygo-social-feed/pub/library/masonry.pkgd.min.js?ver=1.1compygo-social-feed/pub/library/image-loader.min.js?ver=1.1compygo-social-feed/pub/library/slick.min.js?ver=1.1HTML / DOM Fingerprints
cgusf-feed-container<!-- Social Feed for WordPress by CompyGo -->data-cgusf-feed-idcgusf_ajax_obj[compygo-social-feed