
Curator.io Security & Risk Analysis
wordpress.org/plugins/curatorioAggregate and embed your social media posts on your site (Facebook, Twitter, Instagram, Pinterest and many more) as a beautiful social media feed.
Is Curator.io Safe to Use in 2026?
Generally Safe
Score 98/100Curator.io has a strong security track record. Known vulnerabilities have been patched promptly.
The curatorio plugin version 1.9.6 exhibits a generally good security posture based on the static analysis. It demonstrates strong adherence to secure coding practices by using prepared statements for all SQL queries and ensuring that all output is properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further reduces the attack surface. The presence of a nonce check is also a positive indicator.
However, the vulnerability history presents a significant concern. The plugin has two known medium-severity vulnerabilities, both related to Cross-site Scripting (XSS). While there are currently no unpatched CVEs, the existence of past vulnerabilities, especially of a common type like XSS, suggests a recurring weakness that attackers might exploit if not diligently addressed. The fact that the last vulnerability was recorded as 2025-12-31 00:00:00, implying a future date, is highly unusual and could indicate an error in the data source or a placeholder for a recently discovered but not yet patched vulnerability. This historical pattern warrants caution and ongoing vigilance.
In conclusion, while the current code quality is commendable in terms of preventing common vulnerabilities like SQL injection and XSS through proper coding, the past vulnerability record is a critical weakness. Users should ensure all past vulnerabilities are thoroughly patched and remain updated on any new findings. The plugin's limited attack surface (one shortcode) is a positive aspect, but the historical vulnerability data necessitates a cautious approach.
Key Concerns
- Past medium severity XSS vulnerabilities
- Unusual future vulnerability date
Curator.io Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Curator.io <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Curator.io: Show all your social media posts in a beautiful feed. <= 1.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via feed_id Attribute
Curator.io Code Analysis
Output Escaping
Curator.io Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Curator.io Maintenance & Trust
Maintenance Signals
Community Trust
Curator.io Alternatives
Walls.io: Social Media Feed
wallsio
Embed Walls.io social walls into WordPress posts with just one click!
Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds
tagembed-widget
Collect & Embed Instagram Feed, Embed Facebook Feed, Embed YouTube Videos, Embed Twitter Feed, Google Reviews & 15+ Social Media Feed on website.
EmbedSocial – Social Media Feeds, Reviews and Galleries
embedalbum-pro
EmbedSocial allows you to collect and embed social media content on any website automatically.
Iframely – WP media embeds, cards and blocks
iframely
Iframely cloud extends WordPress embeds with customizable embed blocks for over 1900 rich media publishers. For the rest of the Internet, Iframely sho …
Taggbox: Social Feed Widgets
taggbox-widget
Collect, Curate & Publish Instagram, Facebook Feeds, YouTube Videos, Twitter (X) Feeds, Google Reviews & 20+ Social Media Widgets on your website.
Curator.io Developer Profile
1 plugin · 2K total installs
How We Detect Curator.io
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/curatorio/inc/feed.php/wp-content/plugins/curatorio/inc/settings.php/wp-content/plugins/curatorio/inc/shortcode.phphttps://cdn.curator.io/published/HTML / DOM Fingerprints
crt-logodata-crt-feed-iddata-crt-sourceCuratorFeedCuratorPluginCuratorShortcode<div id="curator-feed-default"<a href="https://curator.io" target="_blank" class="crt-logo">Powered by Curator.io</a><script>(function(){var i, e, d = document, s = "script";i = d.createElement("script");i.async = 1;i.src = "https://cdn.curator.io/published/<div id="curator-feed-default" data-crt-feed-id="