HT Feed Security & Risk Analysis

wordpress.org/plugins/ht-instagram

WP Instagram is a elementor addons, visual composer addons, WordPress Default widgets and Ready Shortcode for WordPress.

800 active installs v1.3.1 PHP + WP 5.0+ Updated Dec 4, 2025
elementorinstagraminstagram-feedwordpress-instagramwp-instagram
97
A · Safe
CVEs total3
Unpatched0
Last CVESep 26, 2025
Safety Verdict

Is HT Feed Safe to Use in 2026?

Generally Safe

Score 97/100

HT Feed has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Sep 26, 2025Updated 4mo ago
Risk Assessment

The "ht-instagram" plugin v1.3.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in its handling of SQL queries, utilizing prepared statements exclusively, and it has no known unpatched vulnerabilities. The limited attack surface, with only one shortcode entry point and no unprotected AJAX handlers or REST API routes, is also a strength. However, the static analysis reveals a significant concern with the use of the `create_function()` dangerous function, which can be a vector for code injection if not handled with extreme care. While taint analysis found no flows, the presence of this function alone introduces risk. The vulnerability history shows a pattern of three past medium-severity vulnerabilities, specifically Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). This historical trend suggests a recurring need for robust input validation and output escaping, even though the current analysis indicates a high percentage of properly escaped outputs. The fact that all past vulnerabilities are patched is encouraging, but the types of past vulnerabilities (XSS, CSRF) align with potential issues stemming from improper input handling or lack of proper authorization, which is somewhat contradicted by the positive findings in nonce and capability checks in the current static analysis. Overall, while the current version appears to have addressed past issues and shows good core practices, the `create_function()` usage warrants careful attention and potential remediation.

Key Concerns

  • Presence of dangerous function create_function()
  • Past medium severity XSS vulnerabilities
  • Past medium severity CSRF vulnerabilities
Vulnerabilities
3

HT Feed Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-60147medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

HT Feed <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 26, 2025 Patched in 1.3.1 (13d)
CVE-2024-35699medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

HT Feed <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jun 6, 2024 Patched in 1.2.9 (8d)
CVE-2023-23804medium · 4.3Cross-Site Request Forgery (CSRF)

HT Feed <= 1.2.7 - Cross-Site Request Forgery leading to Limited Plugin Activation

Mar 16, 2023 Patched in 1.2.8 (313d)
Code Analysis
Analyzed Mar 16, 2026

HT Feed Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
52
208 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

create_function$callback = create_function('', 'echo "' . str_replace( '"', '\"', $section['desc'] ) . '";');admin\include\class.settings-api.php:105

Output Escaping

80% escaped260 total outputs
Attack Surface

HT Feed Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[htinstagram] include\shortcode.php:241
WordPress Hooks 13
actionadmin_enqueue_scriptsadmin\admin-init.php:8
actionadmin_initadmin\include\admin-setting.php:15
actionadmin_menuadmin\include\admin-setting.php:16
actionwsa_form_bottom_htinstagram_shortcodeopt_tabsadmin\include\admin-setting.php:17
actioninitadmin\include\admin-setting.php:18
actionadmin_enqueue_scriptsadmin\include\class.settings-api.php:28
actionadmin_menuadmin\include\Recommended_Plugins.php:78
actionadmin_enqueue_scriptsadmin\include\Recommended_Plugins.php:79
actionelementor/widgets/registerht-instagram.php:51
actionelementor/widgets/widgets_registeredht-instagram.php:53
actionwp_enqueue_scriptsht-instagram.php:92
actionwidgets_initinclude\default_widgets.php:253
actioninitinclude\vc_map.php:446
Maintenance & Trust

HT Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version
Downloads34K

Community Trust

Rating0/100
Number of ratings0
Active installs800
Developer Profile

HT Feed Developer Profile

HT Plugins

23 plugins · 64K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
124 days
View full developer profile
Detection Fingerprints

How We Detect HT Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ht-instagram/assests/css/ht-instagramfeed.css/wp-content/plugins/ht-instagram/assests/css/font-awesome.min.css/wp-content/plugins/ht-instagram/assests/css/slick.min.css/wp-content/plugins/ht-instagram/assests/js/slick.min.js/wp-content/plugins/ht-instagram/assests/js/jquery.instagramFeed.min.js/wp-content/plugins/ht-instagram/assests/js/active.js/wp-content/plugins/ht-instagram/admin/assets/css/admin_optionspanel.css
Script Paths
jquery.instagramFeed.min.jsslick.min.jsactive.js
Version Parameters
ht-instagram/assests/css/ht-instagramfeed.css?ver=ht-instagram/assests/css/font-awesome.min.css?ver=ht-instagram/assests/css/slick.min.css?ver=ht-instagram/assests/js/slick.min.js?ver=ht-instagram/assests/js/jquery.instagramFeed.min.js?ver=ht-instagram/assests/js/active.js?ver=ht-instagram/admin/assets/css/admin_optionspanel.css?ver=

HTML / DOM Fingerprints

CSS Classes
ht-instagram-feed
Data Attributes
data-settings
JS Globals
ht_instagram_data
FAQ

Frequently Asked Questions about HT Feed