
Spotlight Social Feeds – Block, Shortcode, and Widget Security & Risk Analysis
wordpress.org/plugins/spotlight-social-photo-feedsInstagram feeds made easy. Responsive, customizable, accessible, and SEO-friendly out of the box. Includes Instagram blocks & oEmbed support.
Is Spotlight Social Feeds – Block, Shortcode, and Widget Safe to Use in 2026?
Generally Safe
Score 98/100Spotlight Social Feeds – Block, Shortcode, and Widget has a strong security track record. Known vulnerabilities have been patched promptly.
The Spotlight Social Photo Feeds plugin, version 1.7.5, presents a mixed security posture. On the positive side, it exhibits good practices by having zero identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. Furthermore, the vast majority of its SQL queries utilize prepared statements, and it includes a reasonable number of capability checks and nonce checks, suggesting some attention to securing its functionalities. The absence of critical or high severity taint analysis findings is also encouraging.
However, several concerns temper this positive outlook. The presence of a `unserialize` function is a significant risk, as it can be exploited for remote code execution if it processes untrusted input. The static analysis also reveals a concerningly low rate of proper output escaping (41%), which can leave the plugin vulnerable to Cross-Site Scripting (XSS) attacks. The vulnerability history, with three known medium severity CVEs including Exposure of Sensitive Information, CSRF, and XSS, even though currently patched, indicates a pattern of past security weaknesses. The bundled Freemius library also needs to be monitored for its own security posture and potential vulnerabilities.
In conclusion, while the plugin has made strides in reducing its direct attack surface and securing its database interactions, the `unserialize` function and poor output escaping represent significant vulnerabilities that could be exploited. The past vulnerability history also suggests a need for ongoing vigilance and thorough code audits. The plugin is not inherently insecure, but these specific issues require immediate attention and mitigation.
Key Concerns
- Use of unserialize function
- Low percentage of properly escaped output
- Past medium severity CVEs
- Bundled Freemius library (potential for outdatedness)
Spotlight Social Feeds – Block, Shortcode, and Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Spotlight Social Media Feeds <= 1.7.1 - Unauthenticated Sensitive Information Disclosure
Spotlight Social Media Feeds <= 1.6.10 - Cross-Site Request Forgery
Spotlight Social Feeds <= 1.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Spotlight Social Feeds – Block, Shortcode, and Widget Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Spotlight Social Feeds – Block, Shortcode, and Widget Attack Surface
WordPress Hooks 56
Maintenance & Trust
Spotlight Social Feeds – Block, Shortcode, and Widget Maintenance & Trust
Maintenance Signals
Community Trust
Spotlight Social Feeds – Block, Shortcode, and Widget Alternatives
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Social Feed Gallery
insta-gallery
Formerly known as "Instagram Feed", this is the best plugin for displaying Instagram feeds on WordPress. It also supports Instagram reels.
WPZOOM Social Feed Widget & Block
instagram-widget-by-wpzoom
Instagram feed plugin for WordPress: Display your Instagram photos, videos & reels. Easy setup with Gutenberg block, widget, shortcode & Elementor
Meks Easy Photo Feed Widget
meks-easy-instagram-widget
Easily display Instagram photos as a widget that looks good in (almost) any WordPress theme.
Widgets for Social Photo Feed
social-photo-feed-widget
Instagram Feed Widgets. Display your Instagram feed on your website to increase engagement, sales and SEO.
Spotlight Social Feeds – Block, Shortcode, and Widget Developer Profile
2 plugins · 110K total installs
How We Detect Spotlight Social Feeds – Block, Shortcode, and Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/spotlight-social-photo-feeds/resources/css/admin.css/wp-content/plugins/spotlight-social-photo-feeds/resources/css/frontend.css/wp-content/plugins/spotlight-social-photo-feeds/resources/js/frontend.js/wp-content/plugins/spotlight-social-photo-feeds/resources/js/admin.js/wp-content/plugins/spotlight-social-photo-feeds/resources/js/admin.js/wp-content/plugins/spotlight-social-photo-feeds/resources/js/frontend.js/wp-content/plugins/spotlight-social-photo-feeds/resources/css/admin.css?ver=/wp-content/plugins/spotlight-social-photo-feeds/resources/css/frontend.css?ver=/wp-content/plugins/spotlight-social-photo-feeds/resources/js/admin.js?ver=/wp-content/plugins/spotlight-social-photo-feeds/resources/js/frontend.js?ver=HTML / DOM Fingerprints
spotlight-instagram-frontendspotlight-instagram-admin<!-- Plugin Name: Spotlight - Social Media Feeds -->data-sl-insta-feedSpotlightInstagramFrontendSpotlightInstagramAdmin/wp-json/spotlight-instagram/v1/feed[instagram-feed