Social Media Feed for WordPress Security & Risk Analysis

wordpress.org/plugins/powr-social-feed

Keep your website content up to date and increase SEO by displaying all of your social media accounts, #hashtags in one place with customized design.

400 active installs v2.1.0 PHP 7.4+ WP 6.7+ Updated Apr 21, 2025
facebook-feedinstagraminstagram-feedsocial-feedtiktok-feed
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Media Feed for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

Social Media Feed for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

Thepowr-social-feed plugin v2.1.0 demonstrates a strong adherence to several key security best practices. The absence of dangerous functions, file operations, external HTTP requests, and the exclusive use of prepared statements for SQL queries are all positive indicators. Furthermore, 100% output escaping and the lack of bundled libraries further bolster its security posture. The vulnerability history is also exceptionally clean, with no recorded CVEs, suggesting a well-maintained and secure codebase. However, the static analysis does reveal two flows with unsanitized paths. While the taint analysis did not escalate these to critical or high severity, this warrants attention as it represents a potential entry point for unexpected behavior or future vulnerabilities if the input is not handled with extreme care. The complete lack of entry points (AJAX handlers, REST API routes, shortcodes, cron events) is a double-edged sword; while it minimizes the attack surface, it also means that any future additions to these areas will need meticulous security implementation, including nonces and capability checks, which are currently absent.

Key Concerns

  • Unsanitized paths in taint analysis
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Social Media Feed for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Social Media Feed for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped9 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
powriosf_powr_social_feed_options (powr-social-feed.php:84)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Social Media Feed for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menupowr-social-feed.php:109
Maintenance & Trust

Social Media Feed for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 21, 2025
PHP min version7.4
Downloads24K

Community Trust

Rating82/100
Number of ratings22
Active installs400
Developer Profile

Social Media Feed for WordPress Developer Profile

POWR

5 plugins · 1K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
65 days
View full developer profile
Detection Fingerprints

How We Detect Social Media Feed for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/powr-social-feed/src/icons/powr-icon.png

HTML / DOM Fingerprints

Data Attributes
style="background: white;display:block; width: calc(100% - -20px); height: calc(100vh - 35px); margin-left: -20px;"
FAQ

Frequently Asked Questions about Social Media Feed for WordPress