
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress Security & Risk Analysis
wordpress.org/plugins/custom-facebook-feedFormerly "Custom Facebook Feed". Display completely customizable Facebook feeds of a Facebook page. Supports Facebook oEmbeds.
Is Smash Balloon Social Post Feed – Simple Social Feeds for WordPress Safe to Use in 2026?
Generally Safe
Score 95/100Smash Balloon Social Post Feed – Simple Social Feeds for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The "custom-facebook-feed" v4.7.6 plugin exhibits a mixed security posture. While it demonstrates good practices like a significant number of nonce and capability checks, and a reasonable percentage of SQL queries using prepared statements and proper output escaping, there are several concerning areas. The presence of 3 AJAX handlers without authentication checks is a significant risk, creating direct entry points for potential attackers. Furthermore, the taint analysis revealed 5 high-severity flows with unsanitized paths, indicating potential for vulnerability if these flows are exposed to user input. The plugin's vulnerability history, with 8 known medium-severity CVEs across common types like missing authorization and cross-site scripting, suggests a recurring pattern of security weaknesses that require ongoing attention and vigilance. While the current version has no unpatched CVEs and the latest vulnerability was in the future (likely a typo and referring to a past date), this history warrants caution. Overall, the plugin has strengths in its implemented checks, but the identified unprotected entry points and high-severity taint flows, coupled with past vulnerability trends, necessitate careful monitoring and prompt patching of any future disclosures.
Key Concerns
- Unprotected AJAX handlers present
- High severity taint flows with unsanitized paths
- Multiple past medium severity CVEs
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
8 total CVEs
Smash Balloon Social Post Feed <= 4.3.2 - Missing Authorization
Smash Balloon Custom Facebook Feed <= 4.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-color` Attribute
Smash Balloon Social Post Feed <= 4.2.1 - Cross-Site Request Forgery
Smash Balloon Social Post Feed <= 4.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Smash Balloon Social Post Feed <= 4.1 - Reflected Cross-Site Scripting
Smash Balloon Social Post Feed <= 4.0 - Arbitrary Plugin Settings Update to Stored Cross-Site Scripting
Smash Balloon Social Post Feed <= 2.19.1 - Unauthenticated Stored Cross-Site Scripting
Smash Balloon Plugins (Various Versions) - Reflected Cross-Site Scripting
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress Attack Surface
AJAX Handlers 54
Shortcodes 1
WordPress Hooks 89
Scheduled Events 10
Maintenance & Trust
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress Alternatives
Mitsol Social Post Feed
facebook-wall-and-social-integration
Formerly known as Facebook wall and social integration allows you to display completely customizable Facebook feed of any public Facebook page or grou …
Mirror App – Social Page
mirror-app-social-page
Display your social page updates — including your full Facebook Feed with posts, photos, and videos — beautifully on your WordPress site using a simpl …
Easy Social Feed – Social Photos Gallery and Post Feed for WordPress
easy-facebook-likebox
Display Instagram, Facebook & YouTube feeds with photos, videos, reels, events & galleries. Fast, responsive & easy to set up.
Mongoose Page Plugin
facebook-page-feed-graph-api
The most popular way to display the Facebook Page Plugin on your WordPress website. Easy implementation using a shortcode or widget.
Social Feed for WordPress by CompyGo
compygo-social-feed
Display completely customizable Facebook Feed on your WordPress website. Also it supports Instagram photos and Youtube videos.
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress Developer Profile
94 plugins · 23.5M total installs
How We Detect Smash Balloon Social Post Feed – Simple Social Feeds for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-facebook-feed/admin/assets/css/cff-admin-style.css/wp-content/plugins/custom-facebook-feed/admin/assets/js/cff-admin-scripts.js/wp-content/plugins/custom-facebook-feed/admin/enqueu-script.php/wp-content/plugins/custom-facebook-feed/inc/Custom_Facebook_Feed.phphttps://maxcdn.bootstrapcdn.com/font-awesome/4.5.0/css/font-awesome.min.csscustom-facebook-feed/admin/assets/css/cff-admin-style.css?ver=custom-facebook-feed/admin/assets/js/cff-admin-scripts.js?ver=HTML / DOM Fingerprints
cff_facebook_feed_locatorcff-feed-wrap<!-- Custom Facebook Feed -->data-cff-idcffA[custom-facebook-feed