Mitsol Social Post Feed Security & Risk Analysis

wordpress.org/plugins/facebook-wall-and-social-integration

Formerly known as Facebook wall and social integration allows you to display completely customizable Facebook feed of any public Facebook page or grou …

200 active installs v1.12 PHP + WP 3.1+ Updated Nov 3, 2025
facebookfacebook-feedfacebook-pagefacebook-postsfacebook-wall
100
A · Safe
CVEs total1
Unpatched0
Last CVEJan 12, 2022
Safety Verdict

Is Mitsol Social Post Feed Safe to Use in 2026?

Generally Safe

Score 100/100

Mitsol Social Post Feed has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 12, 2022Updated 5mo ago
Risk Assessment

The "facebook-wall-and-social-integration" plugin version 1.12 exhibits a mixed security posture. On the positive side, it shows good practices by utilizing prepared statements for all SQL queries and has no known unpatched CVEs. The static analysis reveals a minimal attack surface with no unprotected entry points, and there are no critical or high-severity taint flows identified. However, there are notable concerns, particularly regarding output escaping, where only 25% of outputs are properly escaped. This suggests a significant risk of Cross-Site Scripting (XSS) vulnerabilities, a concern echoed by its vulnerability history which lists one medium-severity XSS vulnerability from early 2022.

The lack of nonce checks across its limited entry points is also a potential weakness, although the attack surface itself is small. The presence of capability checks and external HTTP requests are not inherently risky without further context, but the low percentage of properly escaped output is a primary area of concern. The plugin's history of an XSS vulnerability, combined with the current static analysis findings on output escaping, indicates a recurring weakness that needs attention to prevent potential client-side attacks.

In conclusion, while the plugin avoids common critical security flaws like unpatched CVEs or raw SQL queries, the insufficient output escaping presents a notable risk of XSS vulnerabilities. Addressing this and potentially introducing more robust output sanitization would significantly improve its security. The limited attack surface is a strength, but the potential for XSS due to poor output handling is a significant weakness that detracts from its overall security.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • Past medium severity XSS vulnerability
Vulnerabilities
1

Mitsol Social Post Feed Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-0209medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Mitsol Social Post Feed <= 1.10 - Authenticated (Admin+) Stored Cross-Site Scripting

Jan 12, 2022 Patched in 1.11 (741d)
Code Analysis
Analyzed Mar 16, 2026

Mitsol Social Post Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
136
45 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

25% escaped181 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
facebook_wall_and_social_integration_display_settings (admin\facebook-wall-admin.php:16)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Mitsol Social Post Feed Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mitsol_fbwall_feed_short_code] facebook-wall-and-social-integration.php:43
WordPress Hooks 4
actionadmin_print_stylesfacebook-wall-and-social-integration.php:37
actionadmin_menufacebook-wall-and-social-integration.php:38
filterwidget_textfacebook-wall-and-social-integration.php:46
filterwidget_textfacebook-wall-and-social-integration.php:47
Maintenance & Trust

Mitsol Social Post Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 3, 2025
PHP min version
Downloads39K

Community Trust

Rating100/100
Number of ratings5
Active installs200
Developer Profile

Mitsol Social Post Feed Developer Profile

mitsol

3 plugins · 220 total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
741 days
View full developer profile
Detection Fingerprints

How We Detect Mitsol Social Post Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/facebook-wall-and-social-integration/css/bootstrap.css/wp-content/plugins/facebook-wall-and-social-integration/css/style.css/wp-content/plugins/facebook-wall-and-social-integration/js/social-integration.js/wp-content/plugins/facebook-wall-and-social-integration/js/frontend.js/wp-content/plugins/facebook-wall-and-social-integration/js/jquery.isotope.min.js/wp-content/plugins/facebook-wall-and-social-integration/js/jquery.justifiedGallery.min.js/wp-content/plugins/facebook-wall-and-social-integration/js/jquery.magnific-popup.min.js
Script Paths
/wp-content/plugins/facebook-wall-and-social-integration/js/social-integration.js/wp-content/plugins/facebook-wall-and-social-integration/js/frontend.js/wp-content/plugins/facebook-wall-and-social-integration/js/jquery.isotope.min.js/wp-content/plugins/facebook-wall-and-social-integration/js/jquery.justifiedGallery.min.js/wp-content/plugins/facebook-wall-and-social-integration/js/jquery.magnific-popup.min.js
Version Parameters
facebook-wall-and-social-integration/style.css?ver=facebook-wall-and-social-integration/js/social-integration.js?ver=facebook-wall-and-social-integration/js/frontend.js?ver=facebook-wall-and-social-integration/js/jquery.isotope.min.js?ver=facebook-wall-and-social-integration/js/jquery.justifiedGallery.min.js?ver=facebook-wall-and-social-integration/js/jquery.magnific-popup.min.js?ver=bootstrap.css?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
mitsol-fb-wall-containerfbwasi-social-feedmitsol-fb-wall-postmitsol-social-feed-main-wrapper
HTML Comments
Copyright 2013 mitsol (email : mridulcs@yahoo.com)changed
Data Attributes
data-fb-app-iddata-fb-page-iddata-fb-page-access-tokendata-fb-show-albumsdata-fb-show-eventsdata-fb-show-feed
JS Globals
mitsol_fbwasi_global_variable
Shortcode Output
[mitsol_fbwall_feed_short_code]
FAQ

Frequently Asked Questions about Mitsol Social Post Feed