
Social Photo Fetcher Security & Risk Analysis
wordpress.org/plugins/facebook-photo-fetcherAllows you to automatically create Wordpress photo galleries from Facebook albums. Simple to use and highly customizable.
Is Social Photo Fetcher Safe to Use in 2026?
Mostly Safe
Score 70/100Social Photo Fetcher is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "facebook-photo-fetcher" v3.0.4 plugin presents a mixed security posture. On the positive side, the static analysis shows a clean attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events that are accessible without proper authentication or authorization checks. Furthermore, the plugin avoids dangerous functions and file operations, and all SQL queries utilize prepared statements, which are strong indicators of secure coding practices.
However, significant concerns arise from the output escaping and the vulnerability history. Only 2% of outputs are properly escaped, leaving the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. The taint analysis also indicates unsanitized paths, although currently without critical or high severity. The plugin has a history of known vulnerabilities, with one medium severity CVE currently unpatched. This unpatched vulnerability, coupled with the widespread issue of improper output escaping, significantly increases the risk of exploitation.
In conclusion, while the plugin has a secure entry point design and robust data handling for SQL, the severe lack of output escaping and the presence of an unpatched vulnerability create substantial security risks. The plugin is vulnerable to XSS attacks and the existing unpatched CVE needs immediate attention. Users should exercise extreme caution until these issues are addressed.
Key Concerns
- Unpatched CVE (medium severity)
- Poor output escaping (2% proper)
- Taint flows with unsanitized paths
- No nonce checks on entry points
- No capability checks on entry points
Social Photo Fetcher Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Social Photo Fetcher <= 3.0.4 - Cross-Site Request Forgery
Social Photo Fetcher Code Analysis
Output Escaping
Data Flow Analysis
Social Photo Fetcher Attack Surface
WordPress Hooks 6
Maintenance & Trust
Social Photo Fetcher Maintenance & Trust
Maintenance Signals
Community Trust
Social Photo Fetcher Alternatives
SimpleGal
simplegal
Create an Image-Gallery in 5 simple Steps. Just add the shortcode to your posts.
GPhotos
gphotos
GPhoto is a simple image gallery, easily manageable.
FancyBox for WordPress
fancybox-for-wordpress
Seamlessly integrates FancyBox lightbox into your WordPress blog: Upload, activate, and you're done. Additional configuration optional.
Easy Social Feed – Social Photos Gallery and Post Feed for WordPress
easy-facebook-likebox
Display Instagram, Facebook & YouTube feeds with photos, videos, reels, events & galleries. Fast, responsive & easy to set up.
Lightbox with PhotoSwipe
lightbox-photoswipe
Integration of PhotoSwipe (http://photoswipe.com) for WordPress.
Social Photo Fetcher Developer Profile
3 plugins · 2K total installs
How We Detect Social Photo Fetcher
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/facebook-photo-fetcher/fancybox/jquery.fancybox.min.js/wp-content/plugins/facebook-photo-fetcher/fancybox/jquery.fancybox.min.css/wp-content/plugins/facebook-photo-fetcher/style.css/wp-content/plugins/facebook-photo-fetcher/fancybox/jquery.fancybox.min.jsfacebook-photo-fetcher/style.css?ver=fancybox/jquery.fancybox.min.js?ver=fancybox/jquery.fancybox.min.css?ver=HTML / DOM Fingerprints
fpf-admin_warningfpf-admin_wrapperfpf-admin_tabsfpf-admin_tab_selectedfpf_namefpf_versionfpf_identifierfpf_homepagefpf_apiverfpf_opt_access_token+3 more/wp-json/me?access_token=