My Social Feeds – Social Feeds Embedder Plugin for WordPress Security & Risk Analysis

wordpress.org/plugins/my-social-feeds

Embed Instagram, TikTok, Pinterest, and Twitter feeds easily using Gutenberg blocks.

300 active installs v1.0.3 PHP 7.1+ WP 6.5+ Updated Apr 11, 2026
blockinstagram-feedpinterest-feedtiktok-feedtwitter-feed
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 1, 2026
Download
Safety Verdict

Is My Social Feeds – Social Feeds Embedder Plugin for WordPress Safe to Use in 2026?

Generally Safe

Score 99/100

My Social Feeds – Social Feeds Embedder Plugin for WordPress has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: May 1, 2026Updated 1mo ago
Risk Assessment

The "my-social-feeds" plugin version 1.0.2 exhibits a generally good security posture, with strong adherence to secure coding practices in several key areas. The complete absence of SQL injection vulnerabilities due to the exclusive use of prepared statements and the overwhelmingly proper output escaping (99%) are significant strengths. Furthermore, the lack of any recorded vulnerabilities in its history suggests a well-maintained and historically secure codebase. Taint analysis also shows no critical or high-severity issues, reinforcing this positive impression.

However, a notable concern lies in the plugin's attack surface. With 22 total entry points, 6 of which lack authentication checks, there is a significant risk of unauthorized access or execution of unintended functionality. While nonce checks are present in 16 instances and capability checks in 5, the unprotected AJAX handlers represent a direct pathway for potential attacks if these handlers perform sensitive operations or expose information. The presence of the Freemius SDK also introduces a dependency that, if not properly managed or kept up-to-date, could pose a future risk, although no specific issues are highlighted in the provided data.

In conclusion, "my-social-feeds" v1.0.2 demonstrates commendable secure coding habits in its database and output handling. The primary weakness lies in its exposed attack surface, specifically the unprotected AJAX endpoints. Addressing these requires immediate attention to implement proper authentication and authorization checks on all AJAX handlers. The plugin's historical cleanliness in terms of CVEs is a positive indicator, but vigilance regarding the identified attack surface is paramount.

Key Concerns

  • Unprotected AJAX handlers
Vulnerabilities
1 published

My Social Feeds – Social Feeds Embedder Plugin for WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-6446medium · 5.4Insufficiently Protected Credentials

My Social Feeds <= 1.0.4 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'ttp_get_accounts' AJAX Action

May 1, 2026 Patched in 1.0.5 (1d)
Version History

My Social Feeds – Social Feeds Embedder Plugin for WordPress Release Timeline

v1.0.3Current1 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

My Social Feeds – Social Feeds Embedder Plugin for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
77 escaped
Nonce Checks
16
Capability Checks
5
File Operations
0
External Requests
8
Bundled Libraries
1

Bundled Libraries

Freemius

Output Escaping

99% escaped78 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
fs_init (freemius-lite\inc\Base\FSActivate.php:68)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

My Social Feeds – Social Feeds Embedder Plugin for WordPress Attack Surface

Entry Points22
Unprotected6

AJAX Handlers 21

authwp_ajax_fs_initfreemius-lite\inc\Base\FSActivate.php:42
authwp_ajax_ifbAjaxRequestincludes\Instagram.php:33
noprivwp_ajax_ifbAjaxRequestincludes\Instagram.php:34
authwp_ajax_ifbDeleteTransientincludes\Instagram.php:35
noprivwp_ajax_ifbDeleteTransientincludes\Instagram.php:36
authwp_ajax_msfbp-get-instagram-access-tokenincludes\InstagramAccessTokenSave.php:12
authwp_ajax_msfbp-set-instagram-access-tokenincludes\InstagramAccessTokenSave.php:13
authwp_ajax_msfbp-delete-instagram-access-tokenincludes\InstagramAccessTokenSave.php:14
authwp_ajax_bPinterestAjaxRequestincludes\Pinterest.php:12
noprivwp_ajax_bPinterestAjaxRequestincludes\Pinterest.php:13
authwp_ajax_msfbp-get-pinterest-credentialsincludes\PinterestAccessTokenSave.php:13
authwp_ajax_msfbp-set-pinterest-credentialsincludes\PinterestAccessTokenSave.php:14
authwp_ajax_msfbp-delete-pinterest-credentialsincludes\PinterestAccessTokenSave.php:15
authwp_ajax_ttp_get_accountsincludes\TiktokAPI.php:24
authwp_ajax_ttp_tiktok_videosincludes\TiktokAPI.php:25
noprivwp_ajax_ttp_tiktok_videosincludes\TiktokAPI.php:26
authwp_ajax_ttp_tiktok_clearincludes\TiktokAPI.php:28
authwp_ajax_ttp_remove_accountincludes\TiktokAPI.php:29
authwp_ajax_msfbp-get-twitter-credentialsincludes\TwitterUserNameIdSave.php:12
authwp_ajax_msfbp-set-twitter-credentialsincludes\TwitterUserNameIdSave.php:13
authwp_ajax_msfbp-delete-twitter-credentialsincludes\TwitterUserNameIdSave.php:14

Shortcodes 1

[msfbp-social-feeds] includes\post\shortcode.php:9
WordPress Hooks 28
actionadmin_headfreemius-lite\inc\Base\FSActivate.php:29
actionadmin_enqueue_scriptsfreemius-lite\inc\Base\FSActivate.php:30
actionadmin_menufreemius-lite\inc\Base\FSActivate.php:33
actionadmin_footerfreemius-lite\inc\Base\FSActivate.php:38
actionadmin_footerfreemius-lite\inc\Base\FSActivate.php:39
actionadmin_noticesfreemius-lite\inc\Base\FSActivate.php:44
actioninitfreemius-lite\inc\Base\FS_Lite.php:29
actioninitincludes\Instagram.php:32
actionadmin_menuincludes\menu\admin-menu.php:11
actionadmin_enqueue_scriptsincludes\menu\admin-menu.php:12
filterparent_fileincludes\menu\admin-menu.php:18
filtersubmenu_fileincludes\menu\admin-menu.php:19
actioninitincludes\Pinterest.php:11
actioninitincludes\post\shortcode.php:8
filtermanage_msfbp_posts_columnsincludes\post\shortcode.php:10
actionmanage_msfbp_posts_custom_columnincludes\post\shortcode.php:11
actionuse_block_editor_for_postincludes\post\shortcode.php:12
actionadmin_enqueue_scriptsincludes\post\shortcode.php:13
actionadmin_initincludes\TiktokAPI.php:20
actioninitincludes\TiktokAPI.php:21
actioninitmy-social-feeds.php:94
actionenqueue_block_editor_assetsmy-social-feeds.php:95
actionenqueue_block_assetsmy-social-feeds.php:96
actionenqueue_block_assetsmy-social-feeds.php:97
actionadmin_enqueue_scriptsmy-social-feeds.php:98
actionadmin_footermy-social-feeds.php:99
actionwp_footermy-social-feeds.php:100
filterplugin_action_linksmy-social-feeds.php:101
Maintenance & Trust

My Social Feeds – Social Feeds Embedder Plugin for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 11, 2026
PHP min version7.1
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs300
Developer Profile

My Social Feeds – Social Feeds Embedder Plugin for WordPress Developer Profile

colorlibplugins

121 plugins · 740K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
130 days
View full developer profile
Detection Fingerprints

How We Detect My Social Feeds – Social Feeds Embedder Plugin for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/my-social-feeds/public/css/fancyapps.min.css/wp-content/plugins/my-social-feeds/public/css/justifiedGallery.min.css/wp-content/plugins/my-social-feeds/public/js/fancyapps.min.js/wp-content/plugins/my-social-feeds/public/js/justifiedGallery.min.js/wp-content/plugins/my-social-feeds/public/js/ttp_script.js
Script Paths
https://www.tiktok.com/embed.js
Version Parameters
my-social-feeds/public/js/fancyapps.min.js?ver=my-social-feeds/public/js/justifiedGallery.min.js?ver=my-social-feeds/public/js/ttp_script.js?ver=

HTML / DOM Fingerprints

JS Globals
window.ttpPatterswindow.msfAuthorizationwindow.ttpDatawindow.msfbppipecheck
FAQ

Frequently Asked Questions about My Social Feeds – Social Feeds Embedder Plugin for WordPress