
Feed by Fhoke Security & Risk Analysis
wordpress.org/plugins/feed-by-fhokeDisplays the latest Instagram posts from a user via Instagram Basic Display API.
Is Feed by Fhoke Safe to Use in 2026?
Generally Safe
Score 85/100Feed by Fhoke has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'feed-by-fhoke' plugin version 1.3.3 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and conducting a capability check on its single entry point (a shortcode). The absence of file operations and external HTTP requests further limits its attack surface. The plugin also appears to have no recorded vulnerabilities or CVEs, suggesting a history of secure development or diligent patching.
However, there are areas that warrant attention. A significant portion of the output (36%) is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled securely before being displayed. Additionally, the lack of nonce checks, while not directly tied to AJAX or REST API endpoints in this specific analysis, is a general best practice for securing shortcodes or any function that performs actions on behalf of a user. The bundled Guzzle library, if outdated, could also present a risk, though the analysis doesn't provide version information to confirm this.
In conclusion, 'feed-by-fhoke' is a promising plugin from a security perspective, with no critical vulnerabilities identified and a clear effort towards secure coding practices like prepared statements and capability checks. The primary concern lies in the unescaped output, which requires immediate attention to prevent potential XSS flaws. Addressing this and ensuring the Guzzle library is up-to-date would significantly strengthen its security.
Key Concerns
- Unescaped output detected (36%)
- Bundled library (Guzzle) detected
- Nonce checks are absent
Feed by Fhoke Security Vulnerabilities
Feed by Fhoke Code Analysis
Bundled Libraries
Output Escaping
Feed by Fhoke Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Feed by Fhoke Maintenance & Trust
Maintenance Signals
Community Trust
Feed by Fhoke Alternatives
Intagrate Lite
instagrate-to-wordpress
Automatically post your Instagram images to your WordPress site. Create new WordPress posts from your Instagram images, save the Instagram image to th …
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
WPZOOM Social Feed Widget & Block
instagram-widget-by-wpzoom
Instagram feed plugin for WordPress: Display your Instagram photos, videos & reels. Easy setup with Gutenberg block, widget, shortcode & Elementor
Easy Social Feed – Social Photos Gallery and Post Feed for WordPress
easy-facebook-likebox
Display Instagram, Facebook & YouTube feeds with photos, videos, reels, events & galleries. Fast, responsive & easy to set up.
Widgets for Social Photo Feed
social-photo-feed-widget
Instagram Feed Widgets. Display your Instagram feed on your website to increase engagement, sales and SEO.
Feed by Fhoke Developer Profile
1 plugin · 10 total installs
How We Detect Feed by Fhoke
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feed-by-fhoke/dist/assets/css/shortcode.min.css/wp-content/plugins/feed-by-fhoke/dist/assets/css/admin.min.cssHTML / DOM Fingerprints
fbf-postsfbf-posts__itemfbf-posts__item-linkfbf-posts__item-imgfbf-posts__item-caption<ul class="fbf-posts"><li class="fbf-posts__item"><a class='fbf-posts__item-link' href=<img class='fbf-posts__item-img' src=