
EmbedStories – Display social media stories Security & Risk Analysis
wordpress.org/plugins/embedstoriesEmbedStories allows you to easily embed Instagram Stories on your website
Is EmbedStories – Display social media stories Safe to Use in 2026?
Generally Safe
Score 85/100EmbedStories – Display social media stories has a strong security track record. Known vulnerabilities have been patched promptly.
The "embedstories" plugin v0.7.5 exhibits a generally good security posture with no critical or high-severity issues identified in the static and taint analysis. The absence of dangerous functions, SQL queries without prepared statements, and file operations are positive signs. Furthermore, the high percentage of properly escaped output suggests diligent handling of user-supplied data in many instances. However, there are notable areas of concern that temper this otherwise positive outlook. The complete lack of nonce checks and capability checks across all entry points, particularly the 12 shortcodes, presents a significant risk. This implies that any user, regardless of their role or authentication status, could potentially trigger functionality within these shortcodes, opening the door to unintended actions or information disclosure. While the vulnerability history shows only one medium severity CVE in the past, the presence of a previous XSS vulnerability, even if patched, highlights a potential recurring weakness in input sanitization or output escaping mechanisms that warrants continued vigilance. The fact that there are no currently unpatched vulnerabilities is a positive indicator of maintenance, but the past issues and current lack of robust authentication checks on entry points necessitate careful consideration.
Key Concerns
- No nonce checks on 12 shortcode entry points
- No capability checks on 12 shortcode entry points
- One previous medium severity CVE for XSS
- Low percentage of properly escaped output (92%)
EmbedStories – Display social media stories Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
EmbedStories <= 0.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
EmbedStories – Display social media stories Code Analysis
Output Escaping
EmbedStories – Display social media stories Attack Surface
Shortcodes 12
WordPress Hooks 12
Maintenance & Trust
EmbedStories – Display social media stories Maintenance & Trust
Maintenance Signals
Community Trust
EmbedStories – Display social media stories Alternatives
EmbedSocial – Social Media Feeds, Reviews and Galleries
embedalbum-pro
EmbedSocial allows you to collect and embed social media content on any website automatically.
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Social Feed Gallery
insta-gallery
Formerly known as "Instagram Feed", this is the best plugin for displaying Instagram feeds on WordPress. It also supports Instagram reels.
WPZOOM Social Feed Widget & Block
instagram-widget-by-wpzoom
Instagram feed plugin for WordPress: Display your Instagram photos, videos & reels. Easy setup with Gutenberg block, widget, shortcode & Elementor
Spotlight Social Feeds – Block, Shortcode, and Widget
spotlight-social-photo-feeds
Instagram feeds made easy. Responsive, customizable, accessible, and SEO-friendly out of the box. Includes Instagram blocks & oEmbed support.
EmbedStories – Display social media stories Developer Profile
2 plugins · 4K total installs
How We Detect EmbedStories – Display social media stories
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/embedstories/embedstories.phphttps://embedsocial.com/embedscript/biw.jshttps://embedsocial.com/embedscript/in.jshttps://embedsocial.com/embedscript/ti.jshttps://embedsocial.com/embedscript/eiw.jshttps://embedsocial.com/embedscript/gi.jshttps://embedsocial.com/embedscript/sf.js+6 moreHTML / DOM Fingerprints
embedsocial-albumembedsocial-galleryembedsocial-instagramembedsocial-twitterembedsocial-google-placeembedsocial-socialfeedembedsocial-reviewsembedsocial-google-reviews+4 moredata-ref<div class='embedsocial-album'<div class='embedsocial-gallery'<div class='embedsocial-instagram'<div class='embedsocial-twitter'