Social Post Embed Security & Risk Analysis

wordpress.org/plugins/social-post-embed

Add embedding for various social media platforms to your WordPress posts.

50 active installs v2.0.1 PHP 8.0+ WP 4.6+ Updated Dec 2, 2025
embedsocialspoutiblethreads
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 27, 2026
Safety Verdict

Is Social Post Embed Safe to Use in 2026?

Generally Safe

Score 99/100

Social Post Embed has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 27, 2026Updated 5mo ago
Risk Assessment

The 'social-post-embed' plugin version 2.0.1 exhibits an excellent security posture based on the provided static analysis. The absence of any identified attack surface points, dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly commendable. The code also demonstrates robust output escaping and a lack of exploitable taint flows, indicating diligent security practices by the developers.

The vulnerability history of zero recorded CVEs further strengthens this assessment, suggesting a well-maintained and secure plugin. The complete lack of vulnerabilities in its history, across all severity levels, points to a consistently secure development lifecycle. This plugin appears to be built with security as a primary consideration.

Overall, 'social-post-embed' v2.0.1 presents a very low security risk. Its strengths lie in its minimal attack surface and the absence of any detected vulnerabilities or insecure code patterns. There are no clear weaknesses evident in the provided data that would warrant a security concern for this specific version.

Vulnerabilities
1 published

Social Post Embed Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-6809medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Social Post Embed <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Threads Embed

Apr 27, 2026 Patched in 2.0.2 (10d)
Version History

Social Post Embed Release Timeline

v2.0.1Current1 CVE
v2.01 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Social Post Embed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Social Post Embed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterplugin_row_metainc\shared.php:41
actionadmin_initinc\shared.php:83
actioninitinc\spoutible.php:27
actioninitinc\threads.php:27
Maintenance & Trust

Social Post Embed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version8.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Social Post Embed Developer Profile

David Artiss

10 plugins · 11K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Social Post Embed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-post-embed/inc/threads.php/wp-content/plugins/social-post-embed/inc/spoutible.php/wp-content/plugins/social-post-embed/inc/shared.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Social Post Embed