Sim Social Feed Security & Risk Analysis

wordpress.org/plugins/sim-social-feed

Easily Display Social Media Photo Feed for Instagram. Display Instagram photos in a post page or anywhere else on your WordPress website.

0 active installs v2.9.3 PHP 5.6+ WP 3.4+ Updated Jan 9, 2024
instagraminstagram-feedinstagram-galleryinstagram-photosinstagram-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sim Social Feed Safe to Use in 2026?

Generally Safe

Score 85/100

Sim Social Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "sim-social-feed" v2.9.3 plugin exhibits a generally good security posture based on the provided static analysis. The absence of any known vulnerabilities, critical taint flows, or raw SQL queries is a significant positive. Furthermore, the presence of nonce and capability checks on entry points, along with the use of prepared statements for SQL, indicates adherence to common WordPress security best practices.

However, a concern arises from the output escaping. With 54% of outputs properly escaped, a substantial portion (46%) are not. This leaves the plugin susceptible to Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is directly rendered in the output without proper sanitization. The presence of one shortcode also represents an entry point that, while currently protected by checks, requires careful consideration to ensure no indirect vulnerabilities are introduced through its implementation.

In conclusion, while the plugin benefits from a clean vulnerability history and good practices in data handling and authentication checks, the significant percentage of unescaped output presents a clear and actionable risk. Addressing this area is crucial to improving the plugin's overall security.

Key Concerns

  • Significant percentage of unescaped output (46%)
Vulnerabilities
None known

Sim Social Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Sim Social Feed Release Timeline

v2.9.3Current
v2.8.2
v2.8.1
v2.6.4
v2.5.0
v2.4.5
v2.4.4
v2.4.3
v2.4.1
v2.4.0
v2.3.5
v2.3.4
v1.7.9
v1.7.8
v1.7.5
v1.7.3
Code Analysis
Analyzed Mar 17, 2026

Sim Social Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
34
40 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

54% escaped74 total outputs
Attack Surface

Sim Social Feed Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[igfeed] src\inc\shortcode.php:37
WordPress Hooks 5
actioninitsim-social.php:69
actionsim_social_feed_cronsrc\inc\schedule.php:24
actionadmin_menusrc\WPAdminPage\AdminPage.php:196
actionadmin_enqueue_scriptssrc\WPAdminPage\AdminPage.php:199
actionswa_footersrc\WPAdminPage\AdminPage.php:202

Scheduled Events 1

sim_social_feed_cron
Maintenance & Trust

Sim Social Feed Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedJan 9, 2024
PHP min version5.6
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Sim Social Feed Developer Profile

uri

19 plugins · 1K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sim Social Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sim-social-feed/assets/css/igfeed-gird.css
Version Parameters
sim-social-feed/assets/css/igfeed-gird.css?ver=1.6.3

HTML / DOM Fingerprints

CSS Classes
simsf-grid-itemsimsf-captionsimsf-image-wrapper
Data Attributes
data-limitdata-linksdata-caption
Shortcode Output
[igfeed
FAQ

Frequently Asked Questions about Sim Social Feed