
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin Security & Risk Analysis
wordpress.org/plugins/instagram-feedFormerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Is Smash Balloon Social Photo Feed – Easy Social Feeds Plugin Safe to Use in 2026?
Generally Safe
Score 98/100Smash Balloon Social Photo Feed – Easy Social Feeds Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The 'instagram-feed' plugin v6.10.1 exhibits a mixed security posture. While it demonstrates some good practices such as a significant number of nonce and capability checks, and a majority of SQL queries using prepared statements, there are notable concerns. The presence of one AJAX handler without authentication checks presents a direct entry point for potential exploitation. Furthermore, the taint analysis reveals four high-severity flows with unsanitized paths, indicating potential for serious vulnerabilities like cross-site scripting or insecure direct object references. The plugin's historical vulnerability data, including four known CVEs with one high and three medium severity issues, points to a recurring pattern of security weaknesses, particularly related to Cross-Site Request Forgery and Cross-Site Scripting. Although there are no currently unpatched CVEs, the historical prevalence of these types of vulnerabilities suggests a need for more robust input validation and output escaping mechanisms. Overall, while the plugin has strengths in its defensive checks, the identified unprotected entry point, high-severity taint flows, and historical vulnerability trends warrant careful consideration and prompt remediation.
Key Concerns
- Unprotected AJAX handler
- High severity unsanitized taint flows
- Historical high severity vulnerability
- SQL queries not using prepared statements
- Outputs not properly escaped
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Smash Balloon Plugins (Various Versions) - Reflected Cross-Site Scripting
Smash Balloon Social Photo Feed <= 1.11.3 - Cross-Site Request Forgery to Back-Up Deletion
Smash Balloon Social Photo Feed <= 1.5.1 - Reflected Cross-Site Scripting
Smash Balloon Social Photo Feed <= 1.4.6.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin Attack Surface
AJAX Handlers 57
Shortcodes 1
WordPress Hooks 89
Scheduled Events 15
Maintenance & Trust
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin Alternatives
WPZOOM Social Feed Widget & Block
instagram-widget-by-wpzoom
Instagram feed plugin for WordPress: Display your Instagram photos, videos & reels. Easy setup with Gutenberg block, widget, shortcode & Elementor
Widgets for Social Photo Feed
social-photo-feed-widget
Instagram Feed Widgets. Display your Instagram feed on your website to increase engagement, sales and SEO.
Gutena PhotoFeed
photofeed-block-by-gutena
Gutena PhotoFeed is a free and simple plugin for WordPress that allows you to display your Instagram photos in a gallery. You can set the number of co …
Juicer.io: The Best Social Photo Feed – Posts, Reels, Stories and more
juicer-io-the-best-social-photo-feed-posts-reels-stories-and-more
Display beautiful Instagram feeds on your WordPress site. Support for Instagram Posts, Reels, Stories by @username or #hashtag. Fully customizable.
Social Media Feed Widget
social-media-feed-widget
Formerly \"Social Media Feed Widget \". Display clean, customizable, and responsive Instagram feeds from multiple accounts.
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin Developer Profile
94 plugins · 23.5M total installs
How We Detect Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/instagram-feed/admin/css/sb-admin-styles.css/wp-content/plugins/instagram-feed/admin/css/sb-instagram-admin.css/wp-content/plugins/instagram-feed/admin/js/sb-instagram-admin.js/wp-content/plugins/instagram-feed/css/sb_instagram_feed_styles.css/wp-content/plugins/instagram-feed/css/sb_instagram_frontend.css/wp-content/plugins/instagram-feed/css/sb_instagram_layouts.css/wp-content/plugins/instagram-feed/css/sb_instagram_carousel.css/wp-content/plugins/instagram-feed/css/sb_instagram_photo_feed.css+25 more/wp-content/plugins/instagram-feed/admin/js/sb-instagram-admin.js/wp-content/plugins/instagram-feed/js/sb-instagram-feed.js/wp-content/plugins/instagram-feed/js/sb-instagram-frontend.js/wp-content/plugins/instagram-feed/js/sb-instagram-aio.js/wp-content/plugins/instagram-feed/js/sb-instagram-ajax-pagination.js/wp-content/plugins/instagram-feed/js/sb-instagram-carousel.js+11 moreinstagram-feed/admin/css/sb-admin-styles.css?ver=instagram-feed/admin/css/sb-instagram-admin.css?ver=instagram-feed/admin/js/sb-instagram-admin.js?ver=instagram-feed/css/sb_instagram_feed_styles.css?ver=instagram-feed/css/sb_instagram_frontend.css?ver=instagram-feed/css/sb_instagram_layouts.css?ver=instagram-feed/css/sb_instagram_carousel.css?ver=instagram-feed/css/sb_instagram_photo_feed.css?ver=instagram-feed/css/sb_instagram_shortcode.css?ver=instagram-feed/css/sb_instagram_responsive.css?ver=instagram-feed/js/sb-instagram-feed.js?ver=instagram-feed/js/sb-instagram-frontend.js?ver=instagram-feed/js/sb-instagram-aio.js?ver=instagram-feed/js/sb-instagram-ajax-pagination.js?ver=instagram-feed/js/sb-instagram-carousel.js?ver=instagram-feed/js/sb-instagram-shortcode.js?ver=instagram-feed/js/sb-instagram-photo-feed.js?ver=instagram-feed/js/sb-instagram-initializer.js?ver=instagram-feed/assets/css/sb_instagram_admin.css?ver=instagram-feed/assets/js/sb_instagram_admin.js?ver=instagram-feed/assets/css/sb_instagram_frontend.css?ver=instagram-feed/assets/css/sb_instagram_layouts.css?ver=instagram-feed/assets/css/sb_instagram_carousel.css?ver=instagram-feed/assets/css/sb_instagram_photo_feed.css?ver=instagram-feed/assets/css/sb_instagram_shortcode.css?ver=instagram-feed/assets/css/sb_instagram_responsive.css?ver=instagram-feed/assets/js/sb_instagram_frontend.js?ver=instagram-feed/assets/js/sb_instagram_aio.js?ver=instagram-feed/assets/js/sb_instagram_ajax_pagination.js?ver=instagram-feed/assets/js/sb_instagram_carousel.js?ver=instagram-feed/assets/js/sb_instagram_shortcode.js?ver=instagram-feed/assets/js/sb_instagram_photo_feed.js?ver=instagram-feed/assets/js/sb_instagram_initializer.js?ver=HTML / DOM Fingerprints
sb_instagram_feedsb_instagram_photossbi_photosbi_likessbi_captionsbi_itemsbi_thumbsbi_follow_btn+23 more<!-- Smash Balloon Instagram Feed --><!-- BEGIN: SMASH BALLOON INSTAGRAM FEED --><!-- END: SMASH BALLOON INSTAGRAM FEED --><!-- Smash Balloon Instagram Feed Settings -->data-sbi-iddata-sbi-post-iddata-sbi-embed-iddata-sbi-typedata-sbi-optionsdata-carousel-options+3 moresbInstagramsb_instagram_js_optionsSB_Instagram_Feedsbi_adminsbi_frontend_scripts/wp-json/instagram-feed/v1/feeds/wp-json/instagram-feed/v1/settings/wp-json/instagram-feed/v1/accounts<div class="sb_instagram_feed<div id="sb_instagram_feed<div class="sbi_photo<div class="sb_instagram_photos