
Social Hashtags Security & Risk Analysis
wordpress.org/plugins/social-hashtagsGrabs images & videos matching any hashtag from social APIs like instagram & youtube.
Is Social Hashtags Safe to Use in 2026?
Use With Caution
Score 64/100Social Hashtags has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "social-hashtags" plugin v3.0.0 presents a mixed security posture. While it demonstrates good practices by exclusively using prepared statements for SQL queries and having no file operations or external HTTP requests, significant concerns arise from its attack surface and output sanitization. The presence of an unprotected AJAX handler is a critical vulnerability, as it provides an entry point for unauthenticated attackers to potentially exploit the plugin.
Furthermore, the static analysis reveals that 100% of its nine output operations are not properly escaped. This is a severe weakness that makes the plugin highly susceptible to Cross-Site Scripting (XSS) attacks. The vulnerability history, which includes a medium severity XSS vulnerability from 2012, reinforces these concerns, indicating a recurring pattern of input sanitization issues. While the plugin lacks a large attack surface and complex taint flows, the combination of an unprotected AJAX endpoint and widespread unescaped output creates a substantial risk of compromise.
Key Concerns
- Unprotected AJAX handler
- No properly escaped output
- Unpatched CVE (medium severity)
Social Hashtags Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Social Hashtags <= 3.0.0 - Cross-Site Scripting
Social Hashtags Code Analysis
Output Escaping
Social Hashtags Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Scheduled Events 3
Maintenance & Trust
Social Hashtags Maintenance & Trust
Maintenance Signals
Community Trust
Social Hashtags Alternatives
SocialFeeds
socialfeeds
YouTube feeds for WordPress with simple Setup and Settings options.
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
WPZOOM Social Feed Widget & Block
instagram-widget-by-wpzoom
Instagram feed plugin for WordPress: Display your Instagram photos, videos & reels. Easy setup with Gutenberg block, widget, shortcode & Elementor
Easy Social Feed – Social Photos Gallery and Post Feed for WordPress
easy-facebook-likebox
Display Instagram, Facebook & YouTube feeds with photos, videos, reels, events & galleries. Fast, responsive & easy to set up.
Feed Them Social – Social Media Feeds, Video, and Photo Galleries
feed-them-social
Custom social media feeds for Instagram, Facebook, TikTok, & YouTube. Works with Elementor, Beaver Builder, and Gutenberg blocks.
Social Hashtags Developer Profile
2 plugins · 40 total installs
How We Detect Social Hashtags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-hashtags/lib/social_hashtag.cssHTML / DOM Fingerprints
social_hashtag_ajax