EmbedStories – Display social media stories Security & Risk Analysis

wordpress.org/plugins/embedstories

EmbedStories allows you to easily embed Instagram Stories on your website

300 active installs v0.7.5 PHP + WP 4.0+ Updated Jan 24, 2023
amp-storiesinstagram-storiesinstagram-widgetsocial-media-feedsocial-media-tools
85
A · Safe
CVEs total1
Unpatched0
Last CVEJan 30, 2023
Safety Verdict

Is EmbedStories – Display social media stories Safe to Use in 2026?

Generally Safe

Score 85/100

EmbedStories – Display social media stories has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 30, 2023Updated 3yr ago
Risk Assessment

The "embedstories" plugin v0.7.5 exhibits a generally good security posture with no critical or high-severity issues identified in the static and taint analysis. The absence of dangerous functions, SQL queries without prepared statements, and file operations are positive signs. Furthermore, the high percentage of properly escaped output suggests diligent handling of user-supplied data in many instances. However, there are notable areas of concern that temper this otherwise positive outlook. The complete lack of nonce checks and capability checks across all entry points, particularly the 12 shortcodes, presents a significant risk. This implies that any user, regardless of their role or authentication status, could potentially trigger functionality within these shortcodes, opening the door to unintended actions or information disclosure. While the vulnerability history shows only one medium severity CVE in the past, the presence of a previous XSS vulnerability, even if patched, highlights a potential recurring weakness in input sanitization or output escaping mechanisms that warrants continued vigilance. The fact that there are no currently unpatched vulnerabilities is a positive indicator of maintenance, but the past issues and current lack of robust authentication checks on entry points necessitate careful consideration.

Key Concerns

  • No nonce checks on 12 shortcode entry points
  • No capability checks on 12 shortcode entry points
  • One previous medium severity CVE for XSS
  • Low percentage of properly escaped output (92%)
Vulnerabilities
1

EmbedStories – Display social media stories Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-0372medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

EmbedStories <= 0.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Jan 30, 2023 Patched in 0.7.5 (358d)
Code Analysis
Analyzed Mar 16, 2026

EmbedStories – Display social media stories Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped13 total outputs
Attack Surface

EmbedStories – Display social media stories Attack Surface

Entry Points12
Unprotected0

Shortcodes 12

[embedsocial_album] embedstories.php:286
[embedsocial_gallery] embedstories.php:287
[embedsocial_instagram] embedstories.php:288
[embedsocial_twitter] embedstories.php:289
[embedsocial_google_album] embedstories.php:290
[embedsocial_feed] embedstories.php:291
[embedsocial_reviews] embedstories.php:292
[embedsocial_google_reviews] embedstories.php:293
[embedsocial_custom_reviews] embedstories.php:294
[embedsocial_stories] embedstories.php:295
[embedsocial_stories_popup] embedstories.php:296
[embedsocial_story_gallery] embedstories.php:297
WordPress Hooks 12
actionwp_footerembedstories.php:93
actionwp_footerembedstories.php:109
actionwp_footerembedstories.php:125
actionwp_footerembedstories.php:141
actionwp_footerembedstories.php:157
actionwp_footerembedstories.php:173
actionwp_footerembedstories.php:189
actionwp_footerembedstories.php:205
actionwp_footerembedstories.php:221
actionwp_footerembedstories.php:237
actionwp_footerembedstories.php:253
actionwp_footerembedstories.php:269
Maintenance & Trust

EmbedStories – Display social media stories Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJan 24, 2023
PHP min version
Downloads10K

Community Trust

Rating100/100
Number of ratings3
Active installs300
Developer Profile

EmbedStories – Display social media stories Developer Profile

embedsocial

2 plugins · 4K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
243 days
View full developer profile
Detection Fingerprints

How We Detect EmbedStories – Display social media stories

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/embedstories/embedstories.php
Script Paths
https://embedsocial.com/embedscript/biw.jshttps://embedsocial.com/embedscript/in.jshttps://embedsocial.com/embedscript/ti.jshttps://embedsocial.com/embedscript/eiw.jshttps://embedsocial.com/embedscript/gi.jshttps://embedsocial.com/embedscript/sf.js+6 more

HTML / DOM Fingerprints

CSS Classes
embedsocial-albumembedsocial-galleryembedsocial-instagramembedsocial-twitterembedsocial-google-placeembedsocial-socialfeedembedsocial-reviewsembedsocial-google-reviews+4 more
Data Attributes
data-ref
Shortcode Output
<div class='embedsocial-album'<div class='embedsocial-gallery'<div class='embedsocial-instagram'<div class='embedsocial-twitter'
FAQ

Frequently Asked Questions about EmbedStories – Display social media stories