
Feed Them Social – Social Media Feeds, Video, and Photo Galleries Security & Risk Analysis
wordpress.org/plugins/feed-them-socialCustom social media feeds for Instagram, Facebook, TikTok, & YouTube. Works with Elementor, Beaver Builder, and Gutenberg blocks.
Is Feed Them Social – Social Media Feeds, Video, and Photo Galleries Safe to Use in 2026?
Generally Safe
Score 94/100Feed Them Social – Social Media Feeds, Video, and Photo Galleries has a strong security track record. Known vulnerabilities have been patched promptly.
The "feed-them-social" plugin, version 4.4.1, exhibits a mixed security posture. While the static analysis indicates a strong adherence to security best practices with no unprotected entry points, 90% prepared SQL queries, 87% properly escaped output, and a significant number of nonce and capability checks, there are areas of concern. The presence of 13 taint flows with unsanitized paths, even without critical or high severity, suggests potential for unexpected behavior or minor vulnerabilities if user input is not meticulously handled at every juncture. The plugin also performs 9 external HTTP requests, which, if not properly validated or sanitized, could introduce risks.
The plugin's vulnerability history, however, presents a more significant concern. With 12 known CVEs, including 3 critical and 1 high severity, and a recent vulnerability in January 2024, this indicates a pattern of security weaknesses. The common vulnerability types like CSRF, XSS, Deserialization, and Code Injection are particularly troubling, as they can lead to severe compromises. The fact that there are currently no unpatched CVEs is a positive sign, suggesting prompt remediation for recent issues, but the historical prevalence of severe vulnerabilities is a strong indicator of past systemic issues that may resurface or have underlying causes not immediately apparent in the static analysis of this specific version.
Key Concerns
- 13 taint flows with unsanitized paths
- 12 known CVEs, 3 critical, 1 high
- Recent vulnerability in Jan 2024
- Common vuln types: CSRF, XSS, Deserialization, Code Injection
- 9 external HTTP requests
Feed Them Social – Social Media Feeds, Video, and Photo Galleries Security Vulnerabilities
CVEs by Year
Severity Breakdown
12 total CVEs
Feed Them Social <= 4.2.0 - Cross-Site Request Forgery via review_nag_check
Feed Them Social <= 4.0.7 - Cross-Site Request Forgery
Feed Them Social <= 3.0.2 - Cross-Site Request Forgery
Feed Them Social – for Twitter feed, Youtube and more <= 2.9.9 - Subscriber+ Stored Cross-Site Scripting
Feed Them Social – for Twitter feed, Youtube and more <= 2.9.9 - Cross-Site Request Forgery to Settings update
Feed Them Social – for Twitter feed, Youtube and more <= 2.9.9 - Subscriber+ Stored Cross-Site Scripting
Feed Them Social – for Twitter feed, Youtube and more <= 2.9.8.5 - Unauthenticated PHAR Deserialization
Feed Them Social – for Twitter feed, Youtube and more <= 2.9.8.5 - Cross-Site Request Forgery to Plugin Settings Update
Feed Them Social – for Twitter feed, Youtube and more <= 2.9.9 - Reflected Cross-Site Scripting
Feed Them Social – Page, Post, Video, and Photo Galleries <= 2.8.6 - Cross-Site Request Forgery Bypass
Feed Them Social <= 1.6.9 - Arbitrary Shortcode Execution
Feed Them Social <= 1.6.9 - Reflected Cross-Site Scripting
Feed Them Social – Social Media Feeds, Video, and Photo Galleries Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Feed Them Social – Social Media Feeds, Video, and Photo Galleries Attack Surface
AJAX Handlers 9
Shortcodes 2
WordPress Hooks 74
Maintenance & Trust
Feed Them Social – Social Media Feeds, Video, and Photo Galleries Maintenance & Trust
Maintenance Signals
Community Trust
Feed Them Social – Social Media Feeds, Video, and Photo Galleries Alternatives
YoApy Social Poster
yoapy-social-poster
Schedule and publish posts to Facebook, Instagram, YouTube, and TikTok directly from your WordPress dashboard.
Social Slider Feed
instagram-slider-widget
Display Instagram, Facebook and YouTube feeds in widgets, posts, pages, or anywhere else on your website.
Social Media Feed for WordPress
powr-social-feed
Keep your website content up to date and increase SEO by displaying all of your social media accounts, #hashtags in one place with customized design.
Trollishly Social Media Profile Assistant
trollishly-social-media-profile-assistant
Adds a customizable Follow bar under the post header with TikTok, Instagram, and YouTube profile links configured from the admin settings screen.
Social Login
oa-social-login
With Social Login your users can login, register and comment with 40+ Social Networks. Maintenance Free. Uptime Guarantee. Fulltime devs
Feed Them Social – Social Media Feeds, Video, and Photo Galleries Developer Profile
1 plugin · 20K total installs
How We Detect Feed Them Social – Social Media Feeds, Video, and Photo Galleries
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feed-them-social/admin/css/feed-them-social-admin.css/wp-content/plugins/feed-them-social/admin/js/feed-them-social-admin.js/wp-content/plugins/feed-them-social/feed-them-social.php/wp-content/plugins/feed-them-social/admin/cpt/options/SettingsOptionsJS.php/wp-content/plugins/feed-them-social/admin/js/feed-them-social-admin.jsfeed-them-social/admin/css/feed-them-social-admin.css?ver=feed-them-social/admin/js/feed-them-social-admin.js?ver=HTML / DOM Fingerprints
fts-color-pickerfts-required-extension-wrapfeed-them-social-req-extensionfts-social-selectortabbedfts-show-how-to-messagelike-box-wrapdisplay-comments-wrap+7 moredata-fts-cache-timedata-fts-feed-iddata-fts-ajax-urldata-fts-social-feed-idfts_color_picker[fts_instagram][fts_twitter][fts_facebook][fts_youtube]