Juicer.io: The Best Social Photo Feed – Posts, Reels, Stories and more Security & Risk Analysis

wordpress.org/plugins/juicer-io-the-best-social-photo-feed-posts-reels-stories-and-more

Display beautiful Instagram feeds on your WordPress site. Support for Instagram Posts, Reels, Stories by @username or #hashtag. Fully customizable.

200 active installs v1.0.4 PHP + WP 3.0+ Updated Aug 13, 2025
instagraminstagram-feedinstagram-galleryinstagram-photosinstagram-widget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Juicer.io: The Best Social Photo Feed – Posts, Reels, Stories and more Safe to Use in 2026?

Generally Safe

Score 100/100

Juicer.io: The Best Social Photo Feed – Posts, Reels, Stories and more has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The Juicer.io social photo feed plugin, version 1.0.4, exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and the presence of nonce and capability checks are strong indicators of secure coding practices. Furthermore, the lack of any recorded vulnerabilities, including critical or high severity ones, suggests a history of responsible development or infrequent targeting. The plugin also demonstrates a limited attack surface, with all identified entry points appearing to be protected by authentication or permission checks.

However, a significant concern arises from the low percentage (16%) of properly escaped output. This indicates a potential for cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is displayed without adequate sanitization. While no taint flows were identified in this analysis, the lack of output escaping represents a common vector for attackers to inject malicious scripts. The two external HTTP requests, while not inherently risky, warrant attention in a broader security audit to ensure they are made to trusted endpoints and with appropriate error handling.

In conclusion, the plugin's strengths lie in its robust handling of SQL and its apparent good authentication practices for entry points. The primary weakness lies in the insufficient output escaping, which introduces a notable risk of XSS. While the vulnerability history is clean, this should not detract from addressing the identified output sanitization issue. Addressing the output escaping would significantly strengthen the plugin's security.

Key Concerns

  • Low output escaping percentage
Vulnerabilities
None known

Juicer.io: The Best Social Photo Feed – Posts, Reels, Stories and more Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Juicer.io: The Best Social Photo Feed – Posts, Reels, Stories and more Release Timeline

v1.0.4Current
v1.0.3
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Juicer.io: The Best Social Photo Feed – Posts, Reels, Stories and more Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

16% escaped32 total outputs
Attack Surface

Juicer.io: The Best Social Photo Feed – Posts, Reels, Stories and more Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_juicer_social_feed_dismiss_review_noticejuicer.php:228

Shortcodes 1

[juicer] juicer.php:93
WordPress Hooks 9
actionadmin_menujuicer.php:116
actionadmin_enqueue_scriptsjuicer.php:122
actionadmin_enqueue_scriptsjuicer.php:136
actionadmin_initjuicer.php:175
actionadmin_noticesjuicer.php:203
actionelementor/widgets/registerjuicer.php:249
actionelementor/frontend/after_enqueue_stylesjuicer.php:260
actionelementor/editor/after_enqueue_stylesjuicer.php:261
actionelementor/editor/after_enqueue_scriptsjuicer.php:270
Maintenance & Trust

Juicer.io: The Best Social Photo Feed – Posts, Reels, Stories and more Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 13, 2025
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Juicer.io: The Best Social Photo Feed – Posts, Reels, Stories and more Developer Profile

Juicer.io

2 plugins · 9K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
363 days
View full developer profile
Detection Fingerprints

How We Detect Juicer.io: The Best Social Photo Feed – Posts, Reels, Stories and more

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/juicer-io-the-best-social-photo-feed-posts-reels-stories-and-more/includes/admin/css/admin.css/wp-content/plugins/juicer-io-the-best-social-photo-feed-posts-reels-stories-and-more/includes/admin/js/admin.js
Script Paths
//www.juicer.io/embed/error/wp-plugin-1-12.js
Version Parameters
juicer-io-the-best-social-photo-feed-posts-reels-stories-and-more/includes/admin/css/admin.css?ver=juicer-io-the-best-social-photo-feed-posts-reels-stories-and-more/includes/admin/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
juicer-feed
Data Attributes
data-feed-id
JS Globals
juicer_social_feed_admin
Shortcode Output
<div class="juicer-feed"
FAQ

Frequently Asked Questions about Juicer.io: The Best Social Photo Feed – Posts, Reels, Stories and more