
HT Feed Security & Risk Analysis
wordpress.org/plugins/ht-instagramWP Instagram is a elementor addons, visual composer addons, WordPress Default widgets and Ready Shortcode for WordPress.
Is HT Feed Safe to Use in 2026?
Generally Safe
Score 97/100HT Feed has a strong security track record. Known vulnerabilities have been patched promptly.
The "ht-instagram" plugin v1.3.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in its handling of SQL queries, utilizing prepared statements exclusively, and it has no known unpatched vulnerabilities. The limited attack surface, with only one shortcode entry point and no unprotected AJAX handlers or REST API routes, is also a strength. However, the static analysis reveals a significant concern with the use of the `create_function()` dangerous function, which can be a vector for code injection if not handled with extreme care. While taint analysis found no flows, the presence of this function alone introduces risk. The vulnerability history shows a pattern of three past medium-severity vulnerabilities, specifically Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). This historical trend suggests a recurring need for robust input validation and output escaping, even though the current analysis indicates a high percentage of properly escaped outputs. The fact that all past vulnerabilities are patched is encouraging, but the types of past vulnerabilities (XSS, CSRF) align with potential issues stemming from improper input handling or lack of proper authorization, which is somewhat contradicted by the positive findings in nonce and capability checks in the current static analysis. Overall, while the current version appears to have addressed past issues and shows good core practices, the `create_function()` usage warrants careful attention and potential remediation.
Key Concerns
- Presence of dangerous function create_function()
- Past medium severity XSS vulnerabilities
- Past medium severity CSRF vulnerabilities
HT Feed Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
HT Feed <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
HT Feed <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
HT Feed <= 1.2.7 - Cross-Site Request Forgery leading to Limited Plugin Activation
HT Feed Code Analysis
Dangerous Functions Found
Output Escaping
HT Feed Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
HT Feed Maintenance & Trust
Maintenance Signals
Community Trust
HT Feed Alternatives
Social Feed Gallery
insta-gallery
Formerly known as "Instagram Feed", this is the best plugin for displaying Instagram feeds on WordPress. It also supports Instagram reels.
Inavii for Elementor Social Feed
inavii-social-feed-for-elementor
Create the ultimate Instagram experience. Add Instagram feed to your Elementor site in under 60 seconds and increase your Instagram followers.
Social Feed Widgets For Elementor
social-feed-widgets-for-elementor-using-smash-balloon
Social feed widgets display Instagram profile feed grid or carousel inside Elementor using Smash Balloon social photo feed plugin.
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
WPZOOM Social Feed Widget & Block
instagram-widget-by-wpzoom
Instagram feed plugin for WordPress: Display your Instagram photos, videos & reels. Easy setup with Gutenberg block, widget, shortcode & Elementor
HT Feed Developer Profile
23 plugins · 64K total installs
How We Detect HT Feed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ht-instagram/assests/css/ht-instagramfeed.css/wp-content/plugins/ht-instagram/assests/css/font-awesome.min.css/wp-content/plugins/ht-instagram/assests/css/slick.min.css/wp-content/plugins/ht-instagram/assests/js/slick.min.js/wp-content/plugins/ht-instagram/assests/js/jquery.instagramFeed.min.js/wp-content/plugins/ht-instagram/assests/js/active.js/wp-content/plugins/ht-instagram/admin/assets/css/admin_optionspanel.cssjquery.instagramFeed.min.jsslick.min.jsactive.jsht-instagram/assests/css/ht-instagramfeed.css?ver=ht-instagram/assests/css/font-awesome.min.css?ver=ht-instagram/assests/css/slick.min.css?ver=ht-instagram/assests/js/slick.min.js?ver=ht-instagram/assests/js/jquery.instagramFeed.min.js?ver=ht-instagram/assests/js/active.js?ver=ht-instagram/admin/assets/css/admin_optionspanel.css?ver=HTML / DOM Fingerprints
ht-instagram-feeddata-settingsht_instagram_data