SDAweb Social Galleri Feed Security & Risk Analysis

wordpress.org/plugins/sdaweb-social-galleri-feed

Display your Instagram feed as a beautiful, responsive gallery with lightbox, carousel support, instant loading, and full admin control.

40 active installs v4.8.0 PHP 7.4+ WP 5.8+ Updated Mar 13, 2026
feedgalleryinstagramlightboxsocial-media
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is SDAweb Social Galleri Feed Safe to Use in 2026?

Generally Safe

Score 100/100

SDAweb Social Galleri Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 22d ago
Risk Assessment

The "sdaweb-social-galleri-feed" v4.10.1 plugin demonstrates several positive security practices, including 100% proper output escaping and the exclusive use of prepared statements for all SQL queries. The absence of known CVEs and a clean vulnerability history further suggest a generally secure codebase. However, a notable concern exists within the plugin's attack surface. A significant portion of its entry points, specifically 3 out of 5 AJAX handlers and 1 REST API route, lack proper authentication or permission checks. This leaves them potentially vulnerable to unauthorized access and exploitation if an attacker can directly interact with these unprotected endpoints. Furthermore, while no critical or high severity taint flows were identified, the presence of 6 unsanitized path flows across 7 analyzed flows warrants attention, as path manipulation vulnerabilities can have serious consequences.

Key Concerns

  • Unprotected AJAX handlers
  • Unprotected REST API route
  • Unsanitized path flows detected
Vulnerabilities
None known

SDAweb Social Galleri Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SDAweb Social Galleri Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
426 escaped
Nonce Checks
6
Capability Checks
4
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped427 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

7 flows6 with unsanitized paths
save_token_option (includes\class-admin-settings.php:415)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

SDAweb Social Galleri Feed Attack Surface

Entry Points8
Unprotected4

AJAX Handlers 5

authwp_ajax_sdawsoga_test_connectionincludes\class-admin-settings.php:70
authwp_ajax_sdawsoga_get_layout_configincludes\class-admin-settings.php:71
authwp_ajax_sdawsoga_fetch_instagramsdaweb-social-galleri-feed.php:268
noprivwp_ajax_sdawsoga_fetch_instagramsdaweb-social-galleri-feed.php:269
authwp_ajax_sdawsoga_clear_cachesdaweb-social-galleri-feed.php:270

REST API Routes 1

GET/wp-json/sdawsoga/v1/feedincludes\class-api-handler.php:49

Shortcodes 2

[sdawsoga_gallery] sdaweb-social-galleri-feed.php:273
[tg_gallery] sdaweb-social-galleri-feed.php:274
WordPress Hooks 9
actionadmin_menuincludes\class-admin-settings.php:68
actionadmin_enqueue_scriptsincludes\class-admin-settings.php:69
actionadmin_noticesincludes\class-admin-settings.php:72
actionrest_api_initincludes\class-api-handler.php:26
actioninitincludes\class-api-handler.php:30
actioninitincludes\class-block-registration.php:19
actionadmin_initsdaweb-social-galleri-feed.php:253
actionwp_enqueue_scriptssdaweb-social-galleri-feed.php:256
actionwp_headsdaweb-social-galleri-feed.php:259
Maintenance & Trust

SDAweb Social Galleri Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version7.4
Downloads657

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

SDAweb Social Galleri Feed Developer Profile

rstake

2 plugins · 80 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SDAweb Social Galleri Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sdaweb-social-galleri-feed/js/sda-gallery.js/wp-content/plugins/sdaweb-social-galleri-feed/css/sda-gallery.css/wp-content/plugins/sdaweb-social-galleri-feed/css/sda-gallery-admin.css
Script Paths
/wp-content/plugins/sdaweb-social-galleri-feed/js/sda-gallery.js
Version Parameters
sdaweb-social-galleri-feed/js/sda-gallery.js?ver=sdaweb-social-galleri-feed/css/sda-gallery.css?ver=sdaweb-social-galleri-feed/css/sda-gallery-admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
sdawsoga-gallery-containersdawsoga-gallery-itemsdawsoga-gallery-header
HTML Comments
SDAweb Social Galleri Feed Plugin
Data Attributes
data-sdawsoga-options
JS Globals
sdawsoga_gallery_options
Shortcode Output
[sdawsoga_display_gallery]
FAQ

Frequently Asked Questions about SDAweb Social Galleri Feed