
Widgets for Social Photo Feed Security & Risk Analysis
wordpress.org/plugins/social-photo-feed-widgetInstagram Feed Widgets. Display your Instagram feed on your website to increase engagement, sales and SEO.
Is Widgets for Social Photo Feed Safe to Use in 2026?
Mostly Safe
Score 71/100Widgets for Social Photo Feed is generally safe to use. 3 past CVEs were resolved.
The 'social-photo-feed-widget' plugin v1.7.9 exhibits a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries with prepared statements and ensuring all output is properly escaped, which significantly reduces the risk of common injection and cross-site scripting vulnerabilities. The presence of numerous nonce and capability checks across its code is also a strong indicator of security-conscious development.
However, a critical concern emerges from the static analysis revealing one AJAX handler that lacks authentication checks. This creates a direct, unprotected entry point into the plugin's functionality, potentially allowing unauthorized users to trigger actions. Furthermore, the taint analysis indicates two flows with unsanitized paths, though they are not classified as critical or high severity, they still warrant attention as they could lead to unexpected behavior or data exposure.
The vulnerability history reveals a previously disclosed medium-severity CVE related to missing authorization, and importantly, this vulnerability remains unpatched. This pattern of authorization issues, coupled with the current finding of an unprotected AJAX handler, strongly suggests a recurring weakness in the plugin's authorization mechanisms. While the plugin has strengths in code sanitization and escaping, the persistent authorization flaws and the presence of an unprotected entry point significantly elevate the risk.
Key Concerns
- Unprotected AJAX handler
- Unpatched CVE: Missing Authorization
- Taint flow with unsanitized path
- Taint flow with unsanitized path
Widgets for Social Photo Feed Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Widgets for Social Photo Feed <= 1.8 - Missing Authentication to Unauthenticated Plugin Settings Access/Update via trustindex_feed_hook_instagram REST API endpoints
Widgets for Social Photo Feed <= 1.7.9 - Unauthenticated Stored Cross-Site Scripting via feed_data
Widgets for Social Photo Feed <= 1.7.7 - Missing Authorization
Widgets for Social Photo Feed Release Timeline
Widgets for Social Photo Feed Code Analysis
Output Escaping
Data Flow Analysis
Widgets for Social Photo Feed Attack Surface
AJAX Handlers 1
WordPress Hooks 27
Maintenance & Trust
Widgets for Social Photo Feed Maintenance & Trust
Maintenance Signals
Community Trust
Widgets for Social Photo Feed Alternatives
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
WPZOOM Social Feed Widget & Block
instagram-widget-by-wpzoom
Instagram feed plugin for WordPress: Display your Instagram photos, videos & reels. Easy setup with Gutenberg block, widget, shortcode & Elementor
Gutena PhotoFeed
photofeed-block-by-gutena
Gutena PhotoFeed is a free and simple plugin for WordPress that allows you to display your Instagram photos in a gallery. You can set the number of co …
Juicer.io: The Best Social Photo Feed – Posts, Reels, Stories and more
juicer-io-the-best-social-photo-feed-posts-reels-stories-and-more
Display beautiful Instagram feeds on your WordPress site. Support for Instagram Posts, Reels, Stories by @username or #hashtag. Fully customizable.
Social Media Feed Widget
social-media-feed-widget
Formerly \"Social Media Feed Widget \". Display clean, customizable, and responsive Instagram feeds from multiple accounts.
Widgets for Social Photo Feed Developer Profile
34 plugins · 975K total installs
How We Detect Widgets for Social Photo Feed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-photo-feed-widget/css/widget.css/wp-content/plugins/social-photo-feed-widget/css/feed.css/wp-content/plugins/social-photo-feed-widget/css/ti-animation.css/wp-content/plugins/social-photo-feed-widget/css/loader.css/wp-content/plugins/social-photo-feed-widget/js/feed-loader.js/wp-content/plugins/social-photo-feed-widget/js/feed-loader.jssocial-photo-feed-widget/css/widget.css?ver=social-photo-feed-widget/css/feed.css?ver=social-photo-feed-widget/css/ti-animation.css?ver=social-photo-feed-widget/css/loader.css?ver=social-photo-feed-widget/js/feed-loader.js?ver=HTML / DOM Fingerprints
trustindex-feed-containerti-feed-itemti-icon-instagramti-animationtrustindex-notification-rowCopyright 2019 Trustindex Kft (email: support@trustindex.io)This function ensures that each element of the JSON object is sanitized individually using standard WordPress sanitization functionsdata-ti-source-iddata-ti-feed-iddata-ti-feed-typedata-ti-feed-styledata-ti-account-iddata-ti-profile-id+1 moreTRUSTINDEX_Feed_Instagram/wp-json/trustindex-feed-instagram/v1/get-token/wp-json/trustindex-feed-instagram/v1/troubleshooting/wp-json/trustindex-feed-instagram/v1/submit-data/wp-json/trustindex-feed-instagram/v1/refresh-data[social_photo_feed]