
Include Mastodon Feed Security & Risk Analysis
wordpress.org/plugins/include-mastodon-feedPlugin that provides a Gutenberg block and shortcode to easily integrate mastodon feeds into wordpress pages.
Is Include Mastodon Feed Safe to Use in 2026?
Generally Safe
Score 99/100Include Mastodon Feed has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "include-mastodon-feed" plugin v2.1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and generally performing good output escaping (83%). It also has no unpatched CVEs, which is encouraging. However, there are significant areas of concern. The plugin has a total of 2 entry points, with 1 being unprotected, specifically a REST API route without a permission callback. This unprotected endpoint represents a potential attack vector. The lack of any nonce checks and capability checks across the codebase further exacerbates this risk, as it implies that potentially sensitive operations or data exposure could occur without proper authorization. While taint analysis did not reveal any issues in this specific scan, the presence of 2 past medium severity Cross-Site Scripting (XSS) vulnerabilities, with the last one reported in early 2025, suggests a recurring pattern of input sanitization or output escaping deficiencies. The plugin also makes external HTTP requests, which, without clear sanitization and validation of the returned data, could pose a risk if the external resource is compromised or malicious. In conclusion, while the plugin has some solid security foundations, the unprotected REST API endpoint, absence of critical security checks like nonces and capability checks, and past XSS vulnerabilities necessitate caution and further investigation.
Key Concerns
- Unprotected REST API route
- No nonce checks
- No capability checks
- Past XSS vulnerabilities
- External HTTP requests without clear validation
- Low output escaping percentage for some outputs
Include Mastodon Feed Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Include Mastodon Feed <= 1.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Include Mastodon Feed <= 1.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Include Mastodon Feed Release Timeline
Include Mastodon Feed Code Analysis
Output Escaping
Include Mastodon Feed Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Include Mastodon Feed Maintenance & Trust
Maintenance Signals
Community Trust
Include Mastodon Feed Alternatives
Better Press Newsfeed
better-press-newsfeed
A plugin to provide a dashboard widget for WP Tavern and Post Status.
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
Pinterest for WooCommerce
pinterest-for-woocommerce
Get your products in front of Pinterest users searching for ideas and things to buy. Connect your WooCommerce store to make your catalog browsable.
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress
custom-facebook-feed
Formerly "Custom Facebook Feed". Display completely customizable Facebook feeds of a Facebook page. Supports Facebook oEmbeds.
Include Mastodon Feed Developer Profile
1 plugin · 800 total installs
How We Detect Include Mastodon Feed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/include-mastodon-feed/include-mastodon-feed.js/wp-content/plugins/include-mastodon-feed/include-mastodon-feed.css/wp-content/plugins/include-mastodon-feed/include-mastodon-feed.jsinclude-mastodon-feed/include-mastodon-feed.js?ver=include-mastodon-feed/include-mastodon-feed.css?ver=HTML / DOM Fingerprints
window.includeMastodonFeed/wp-json/include-mastodon-feed/v1/feed/