Juicer.io: Effortlessly embed, curate, and aggregate social media feeds into your website Security & Risk Analysis

wordpress.org/plugins/juicer

Aggregate social media posts and hashtags from Instagram, X (Twitter), Facebook, LinkedIn, YouTube, and more into a stunning feed on your website.

9K active installs v1.12.16 PHP + WP 3.0+ Updated Aug 13, 2025
embed-social-mediainstagram-feedlinkedin-feedsocial-media-aggregatorsocial-wall
100
A · Safe
CVEs total1
Unpatched0
Last CVEJan 25, 2023
Safety Verdict

Is Juicer.io: Effortlessly embed, curate, and aggregate social media feeds into your website Safe to Use in 2026?

Generally Safe

Score 100/100

Juicer.io: Effortlessly embed, curate, and aggregate social media feeds into your website has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 25, 2023Updated 7mo ago
Risk Assessment

The Juicer plugin v1.12.16 exhibits a mixed security posture. On the positive side, it demonstrates good practices by employing prepared statements for all SQL queries and includes nonce and capability checks on its single AJAX handler, indicating an effort to secure entry points. Furthermore, there are no critical or high-severity taint flows identified, and the plugin does not appear to bundle any external libraries, which can sometimes introduce vulnerabilities. However, significant concerns arise from the limited output escaping, with only 3% of identified outputs being properly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where unescaped user-provided data could be rendered in the browser, allowing malicious scripts to execute. The plugin's vulnerability history, including a past medium-severity XSS vulnerability, reinforces this concern, indicating a pattern of input sanitization issues. While the plugin currently has no unpatched CVEs, the prevalence of unescaped output presents a tangible and significant risk that needs immediate attention.

In conclusion, while the Juicer plugin shows strengths in database security and securing its limited direct entry points, the severe lack of output escaping creates a substantial security weakness. This, combined with past XSS-related vulnerabilities, suggests that the plugin is susceptible to XSS attacks. The limited number of entry points and the absence of critical taint flows are positive, but they are overshadowed by the high probability of XSS due to insufficient output sanitization. Addressing the unescaped output is paramount to improving the plugin's security posture.

Key Concerns

  • Significant number of unescaped outputs
  • Past medium severity XSS vulnerability
Vulnerabilities
1

Juicer.io: Effortlessly embed, curate, and aggregate social media feeds into your website Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-0172medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Juicer <= 1.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Jan 25, 2023 Patched in 1.11 (363d)
Code Analysis
Analyzed Mar 16, 2026

Juicer.io: Effortlessly embed, curate, and aggregate social media feeds into your website Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
34
1 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

3% escaped35 total outputs
Attack Surface

Juicer.io: Effortlessly embed, curate, and aggregate social media feeds into your website Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_juicer_dismiss_review_noticejuicer.php:231

Shortcodes 1

[juicer] juicer.php:88
WordPress Hooks 9
actionadmin_menujuicer.php:111
actionadmin_enqueue_scriptsjuicer.php:117
actionadmin_enqueue_scriptsjuicer.php:132
actionadmin_initjuicer.php:173
actionadmin_noticesjuicer.php:203
actionelementor/widgets/registerjuicer.php:252
actionelementor/frontend/after_enqueue_stylesjuicer.php:263
actionelementor/editor/after_enqueue_stylesjuicer.php:264
actionelementor/editor/after_enqueue_scriptsjuicer.php:272
Maintenance & Trust

Juicer.io: Effortlessly embed, curate, and aggregate social media feeds into your website Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 13, 2025
PHP min version
Downloads268K

Community Trust

Rating84/100
Number of ratings28
Active installs9K
Developer Profile

Juicer.io: Effortlessly embed, curate, and aggregate social media feeds into your website Developer Profile

Juicer.io

2 plugins · 9K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
363 days
View full developer profile
Detection Fingerprints

How We Detect Juicer.io: Effortlessly embed, curate, and aggregate social media feeds into your website

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/juicer/includes/admin/css/admin.css/wp-content/plugins/juicer/includes/admin/js/admin.js
Script Paths
//www.juicer.io/embed/error/wp-plugin-1-12.js//www.juicer.io/embed/some_feed_name/wp-plugin-1-12.js
Version Parameters
juicer-admin-css?ver=1.12.16juicer-admin-js?ver=1.12.16wp-plugin-1-12.js?nojquery=true&

HTML / DOM Fingerprints

CSS Classes
juicer-feed
HTML Comments
<!-- Only set cookie if headers haven't been sent --><!-- Cookie expires in 1 hour --><!-- Setup menu for admin section --><!-- Load custom admin CSS -->+7 more
Data Attributes
data-feed-id
JS Globals
juicer_admin.ajax_urljuicer_admin.security
REST Endpoints
/api/hosts?hostname=
Shortcode Output
<div class="juicer-feed" data-feed-id="
FAQ

Frequently Asked Questions about Juicer.io: Effortlessly embed, curate, and aggregate social media feeds into your website