SnapWidget Social Photo Feed Widget Security & Risk Analysis

wordpress.org/plugins/snapwidget-wp-instagram-widget

SnapWidget Social Photo Feed Widget is an easy way to embed your Instagram photos and videos on your website or blog to display your photos.

600 active installs v1.1.0 PHP + WP 4.4+ Updated Feb 25, 2021
instagramphotossidebarwidgetwidgets
42
D · High Risk
CVEs total2
Unpatched2
Last CVESep 22, 2025
Safety Verdict

Is SnapWidget Social Photo Feed Widget Safe to Use in 2026?

High Risk

Score 42/100

SnapWidget Social Photo Feed Widget carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.

2 known CVEs 2 unpatched Last CVE: Sep 22, 2025Updated 5yr ago
Risk Assessment

The snapwidget-wp-instagram-widget plugin v1.1.0 presents a mixed security posture. On the positive side, the static analysis reveals good development practices, with no dangerous functions identified, all SQL queries using prepared statements, and a high percentage of output escaping. The attack surface is small, with only one shortcode and no unprotected entry points. However, the plugin's vulnerability history is a significant concern, with two known medium-severity vulnerabilities, both of which remain unpatched. The common vulnerability type being Cross-site Scripting suggests potential issues with how user-supplied data is handled, even if current static analysis didn't flag specific unsanitized paths. The plugin's lack of nonce checks and capability checks is also a notable weakness, especially given its past vulnerabilities.

While the current version's code analysis shows few immediate red flags regarding raw SQL or dangerous functions, the history of two unpatched medium-severity XSS vulnerabilities is a critical indicator of risk. This history strongly suggests that previous security issues were not adequately addressed, and a potential for similar vulnerabilities to exist or be re-introduced is high. The absence of nonce and capability checks on its single entry point (the shortcode) further exacerbates this risk, as it provides an easier path for attackers to exploit any latent vulnerabilities.

In conclusion, while the code exhibits some good practices, the presence of unpatched vulnerabilities and a lack of essential security checks like nonces and capability checks on its entry point create a significant security risk. Users should be strongly advised to avoid this version and seek an updated, patched version, or consider alternative plugins. The current security posture is therefore considered precarious.

Key Concerns

  • Two unpatched medium severity CVEs
  • Vulnerability history indicates XSS issues
  • No nonce checks on entry points
  • No capability checks on entry points
  • 91% output escaping, 9% unescaped
Vulnerabilities
2

SnapWidget Social Photo Feed Widget Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-58241medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SnapWidget Social Photo Feed Widget <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 22, 2025Unpatched
CVE-2025-31760medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SnapWidget Social Photo Feed Widget <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 1, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

SnapWidget Social Photo Feed Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
39 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped43 total outputs
Attack Surface

SnapWidget Social Photo Feed Widget Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[snapwidget-instagram-widget] snapwidget-wp-instagram-widget.php:12
WordPress Hooks 1
actionwidgets_initsnapwidget-wp-instagram-widget.php:15
Maintenance & Trust

SnapWidget Social Photo Feed Widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedFeb 25, 2021
PHP min version
Downloads15K

Community Trust

Rating60/100
Number of ratings2
Active installs600
Developer Profile

SnapWidget Social Photo Feed Widget Developer Profile

snapwidget

1 plugin · 600 total installs

53
trust score
Avg Security Score
42/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SnapWidget Social Photo Feed Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/snapwidget-wp-instagram-widget/snapwidget-wp-instagram-widget.php

HTML / DOM Fingerprints

CSS Classes
snapwidget-widget
Data Attributes
data-field-iddata-field-widthdata-field-heightdata-field-lightbox
Shortcode Output
<iframe src="https://snapwidget.com/embed/" class="snapwidget-widget" allowtransparency="true" frameborder="0" scrolling="no" style="border:none; overflow:hidden; width:
FAQ

Frequently Asked Questions about SnapWidget Social Photo Feed Widget