
Mitsol Social Post Feed Security & Risk Analysis
wordpress.org/plugins/facebook-wall-and-social-integrationFormerly known as Facebook wall and social integration allows you to display completely customizable Facebook feed of any public Facebook page or grou …
Is Mitsol Social Post Feed Safe to Use in 2026?
Generally Safe
Score 100/100Mitsol Social Post Feed has a strong security track record. Known vulnerabilities have been patched promptly.
The "facebook-wall-and-social-integration" plugin version 1.12 exhibits a mixed security posture. On the positive side, it shows good practices by utilizing prepared statements for all SQL queries and has no known unpatched CVEs. The static analysis reveals a minimal attack surface with no unprotected entry points, and there are no critical or high-severity taint flows identified. However, there are notable concerns, particularly regarding output escaping, where only 25% of outputs are properly escaped. This suggests a significant risk of Cross-Site Scripting (XSS) vulnerabilities, a concern echoed by its vulnerability history which lists one medium-severity XSS vulnerability from early 2022.
The lack of nonce checks across its limited entry points is also a potential weakness, although the attack surface itself is small. The presence of capability checks and external HTTP requests are not inherently risky without further context, but the low percentage of properly escaped output is a primary area of concern. The plugin's history of an XSS vulnerability, combined with the current static analysis findings on output escaping, indicates a recurring weakness that needs attention to prevent potential client-side attacks.
In conclusion, while the plugin avoids common critical security flaws like unpatched CVEs or raw SQL queries, the insufficient output escaping presents a notable risk of XSS vulnerabilities. Addressing this and potentially introducing more robust output sanitization would significantly improve its security. The limited attack surface is a strength, but the potential for XSS due to poor output handling is a significant weakness that detracts from its overall security.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks on entry points
- Past medium severity XSS vulnerability
Mitsol Social Post Feed Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Mitsol Social Post Feed <= 1.10 - Authenticated (Admin+) Stored Cross-Site Scripting
Mitsol Social Post Feed Code Analysis
Output Escaping
Data Flow Analysis
Mitsol Social Post Feed Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Mitsol Social Post Feed Maintenance & Trust
Maintenance Signals
Community Trust
Mitsol Social Post Feed Alternatives
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress
custom-facebook-feed
Formerly "Custom Facebook Feed". Display completely customizable Facebook feeds of a Facebook page. Supports Facebook oEmbeds.
Mirror App – Social Page
mirror-app-social-page
Display your social page updates — including your full Facebook Feed with posts, photos, and videos — beautifully on your WordPress site using a simpl …
Easy Social Feed – Social Photos Gallery and Post Feed for WordPress
easy-facebook-likebox
Display Instagram, Facebook & YouTube feeds with photos, videos, reels, events & galleries. Fast, responsive & easy to set up.
Mongoose Page Plugin
facebook-page-feed-graph-api
The most popular way to display the Facebook Page Plugin on your WordPress website. Easy implementation using a shortcode or widget.
Social Feed for WordPress by CompyGo
compygo-social-feed
Display completely customizable Facebook Feed on your WordPress website. Also it supports Instagram photos and Youtube videos.
Mitsol Social Post Feed Developer Profile
3 plugins · 220 total installs
How We Detect Mitsol Social Post Feed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/facebook-wall-and-social-integration/css/bootstrap.css/wp-content/plugins/facebook-wall-and-social-integration/css/style.css/wp-content/plugins/facebook-wall-and-social-integration/js/social-integration.js/wp-content/plugins/facebook-wall-and-social-integration/js/frontend.js/wp-content/plugins/facebook-wall-and-social-integration/js/jquery.isotope.min.js/wp-content/plugins/facebook-wall-and-social-integration/js/jquery.justifiedGallery.min.js/wp-content/plugins/facebook-wall-and-social-integration/js/jquery.magnific-popup.min.js/wp-content/plugins/facebook-wall-and-social-integration/js/social-integration.js/wp-content/plugins/facebook-wall-and-social-integration/js/frontend.js/wp-content/plugins/facebook-wall-and-social-integration/js/jquery.isotope.min.js/wp-content/plugins/facebook-wall-and-social-integration/js/jquery.justifiedGallery.min.js/wp-content/plugins/facebook-wall-and-social-integration/js/jquery.magnific-popup.min.jsfacebook-wall-and-social-integration/style.css?ver=facebook-wall-and-social-integration/js/social-integration.js?ver=facebook-wall-and-social-integration/js/frontend.js?ver=facebook-wall-and-social-integration/js/jquery.isotope.min.js?ver=facebook-wall-and-social-integration/js/jquery.justifiedGallery.min.js?ver=facebook-wall-and-social-integration/js/jquery.magnific-popup.min.js?ver=bootstrap.css?ver=1.0.0HTML / DOM Fingerprints
mitsol-fb-wall-containerfbwasi-social-feedmitsol-fb-wall-postmitsol-social-feed-main-wrapperCopyright 2013 mitsol (email : mridulcs@yahoo.com)changeddata-fb-app-iddata-fb-page-iddata-fb-page-access-tokendata-fb-show-albumsdata-fb-show-eventsdata-fb-show-feedmitsol_fbwasi_global_variable[mitsol_fbwall_feed_short_code]