
My Social Feeds – Social Feeds Embedder Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/my-social-feedsEmbed Instagram, TikTok, Pinterest, and Twitter feeds easily using Gutenberg blocks.
Is My Social Feeds – Social Feeds Embedder Plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 99/100My Social Feeds – Social Feeds Embedder Plugin for WordPress has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "my-social-feeds" plugin version 1.0.2 exhibits a generally good security posture, with strong adherence to secure coding practices in several key areas. The complete absence of SQL injection vulnerabilities due to the exclusive use of prepared statements and the overwhelmingly proper output escaping (99%) are significant strengths. Furthermore, the lack of any recorded vulnerabilities in its history suggests a well-maintained and historically secure codebase. Taint analysis also shows no critical or high-severity issues, reinforcing this positive impression.
However, a notable concern lies in the plugin's attack surface. With 22 total entry points, 6 of which lack authentication checks, there is a significant risk of unauthorized access or execution of unintended functionality. While nonce checks are present in 16 instances and capability checks in 5, the unprotected AJAX handlers represent a direct pathway for potential attacks if these handlers perform sensitive operations or expose information. The presence of the Freemius SDK also introduces a dependency that, if not properly managed or kept up-to-date, could pose a future risk, although no specific issues are highlighted in the provided data.
In conclusion, "my-social-feeds" v1.0.2 demonstrates commendable secure coding habits in its database and output handling. The primary weakness lies in its exposed attack surface, specifically the unprotected AJAX endpoints. Addressing these requires immediate attention to implement proper authentication and authorization checks on all AJAX handlers. The plugin's historical cleanliness in terms of CVEs is a positive indicator, but vigilance regarding the identified attack surface is paramount.
Key Concerns
- Unprotected AJAX handlers
My Social Feeds – Social Feeds Embedder Plugin for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
My Social Feeds <= 1.0.4 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'ttp_get_accounts' AJAX Action
My Social Feeds – Social Feeds Embedder Plugin for WordPress Release Timeline
My Social Feeds – Social Feeds Embedder Plugin for WordPress Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
My Social Feeds – Social Feeds Embedder Plugin for WordPress Attack Surface
AJAX Handlers 21
Shortcodes 1
WordPress Hooks 28
Maintenance & Trust
My Social Feeds – Social Feeds Embedder Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
My Social Feeds – Social Feeds Embedder Plugin for WordPress Alternatives
Spotlight Social Feeds – Block, Shortcode, and Widget
spotlight-social-photo-feeds
Instagram feeds made easy. Responsive, customizable, accessible, and SEO-friendly out of the box. Includes Instagram blocks & oEmbed support.
Walls.io: Social Media Feed
wallsio
Embed Walls.io social walls into WordPress posts with just one click!
Combine Social Photos | Still BE
still-be-combine-social-photos
Provides Instagram embedding functionality exclusively for WP Block Editor. Your feeds, other Pro accounts' feeds and posts related to hashtags.
Social Media Feed for WordPress
powr-social-feed
Keep your website content up to date and increase SEO by displaying all of your social media accounts, #hashtags in one place with customized design.
All in one Social Feeds
all-in-one-social-feeds
This plugin helps to display latest feeds from facebook, twitter,instagram, pinterest and youtube with tabs using a widget.
My Social Feeds – Social Feeds Embedder Plugin for WordPress Developer Profile
121 plugins · 740K total installs
How We Detect My Social Feeds – Social Feeds Embedder Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/my-social-feeds/public/css/fancyapps.min.css/wp-content/plugins/my-social-feeds/public/css/justifiedGallery.min.css/wp-content/plugins/my-social-feeds/public/js/fancyapps.min.js/wp-content/plugins/my-social-feeds/public/js/justifiedGallery.min.js/wp-content/plugins/my-social-feeds/public/js/ttp_script.jshttps://www.tiktok.com/embed.jsmy-social-feeds/public/js/fancyapps.min.js?ver=my-social-feeds/public/js/justifiedGallery.min.js?ver=my-social-feeds/public/js/ttp_script.js?ver=HTML / DOM Fingerprints
window.ttpPatterswindow.msfAuthorizationwindow.ttpDatawindow.msfbppipecheck