
SnapWidget Social Photo Feed Widget Security & Risk Analysis
wordpress.org/plugins/snapwidget-wp-instagram-widgetSnapWidget Social Photo Feed Widget is an easy way to embed your Instagram photos and videos on your website or blog to display your photos.
Is SnapWidget Social Photo Feed Widget Safe to Use in 2026?
High Risk
Score 42/100SnapWidget Social Photo Feed Widget carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The snapwidget-wp-instagram-widget plugin v1.1.0 presents a mixed security posture. On the positive side, the static analysis reveals good development practices, with no dangerous functions identified, all SQL queries using prepared statements, and a high percentage of output escaping. The attack surface is small, with only one shortcode and no unprotected entry points. However, the plugin's vulnerability history is a significant concern, with two known medium-severity vulnerabilities, both of which remain unpatched. The common vulnerability type being Cross-site Scripting suggests potential issues with how user-supplied data is handled, even if current static analysis didn't flag specific unsanitized paths. The plugin's lack of nonce checks and capability checks is also a notable weakness, especially given its past vulnerabilities.
While the current version's code analysis shows few immediate red flags regarding raw SQL or dangerous functions, the history of two unpatched medium-severity XSS vulnerabilities is a critical indicator of risk. This history strongly suggests that previous security issues were not adequately addressed, and a potential for similar vulnerabilities to exist or be re-introduced is high. The absence of nonce and capability checks on its single entry point (the shortcode) further exacerbates this risk, as it provides an easier path for attackers to exploit any latent vulnerabilities.
In conclusion, while the code exhibits some good practices, the presence of unpatched vulnerabilities and a lack of essential security checks like nonces and capability checks on its entry point create a significant security risk. Users should be strongly advised to avoid this version and seek an updated, patched version, or consider alternative plugins. The current security posture is therefore considered precarious.
Key Concerns
- Two unpatched medium severity CVEs
- Vulnerability history indicates XSS issues
- No nonce checks on entry points
- No capability checks on entry points
- 91% output escaping, 9% unescaped
SnapWidget Social Photo Feed Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
SnapWidget Social Photo Feed Widget <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
SnapWidget Social Photo Feed Widget <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
SnapWidget Social Photo Feed Widget Code Analysis
Output Escaping
SnapWidget Social Photo Feed Widget Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
SnapWidget Social Photo Feed Widget Maintenance & Trust
Maintenance Signals
Community Trust
SnapWidget Social Photo Feed Widget Alternatives
Fidgetr
fidgetr
A simple and beautiful Flickr widget that supports themes.
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager
custom-sidebars
Flexible sidebars for custom classic widget configurations on any page or post. Create custom sidebars with ease!
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
WooSidebars
woosidebars
WooSidebars adds functionality to display different widgets in a sidebar, according to a context (for example, a specific page or a category).
SnapWidget Social Photo Feed Widget Developer Profile
1 plugin · 600 total installs
How We Detect SnapWidget Social Photo Feed Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/snapwidget-wp-instagram-widget/snapwidget-wp-instagram-widget.phpHTML / DOM Fingerprints
snapwidget-widgetdata-field-iddata-field-widthdata-field-heightdata-field-lightbox<iframe src="https://snapwidget.com/embed/" class="snapwidget-widget" allowtransparency="true" frameborder="0" scrolling="no" style="border:none; overflow:hidden; width: