Taeggie Feed Security & Risk Analysis

wordpress.org/plugins/taeggie-feed

Taeggie Feed displays a social feed that is configured on and served from reliable taeggie.com servers. Paid plugin with monthly billing.

60 active installs v0.1.11 PHP + WP 2.5+ Updated Jul 30, 2025
facebookinstagramsocial-feedtaeggietwitter
98
A · Safe
CVEs total2
Unpatched0
Last CVEJul 23, 2025
Safety Verdict

Is Taeggie Feed Safe to Use in 2026?

Generally Safe

Score 98/100

Taeggie Feed has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jul 23, 2025Updated 8mo ago
Risk Assessment

The 'taeggie-feed' plugin, version 0.1.11, presents a mixed security profile. On the positive side, the static analysis shows a very small attack surface, with only one shortcode identified and no unprotected entry points. Furthermore, all SQL queries are properly prepared, and there are no obvious signs of dangerous functions, file operations, or external HTTP requests. The absence of critical or high-severity taint flows is also encouraging.

However, significant concerns arise from the plugin's vulnerability history. The presence of two known medium-severity CVEs, specifically related to Cross-Site Scripting (XSS), indicates potential weaknesses in input sanitization and output escaping, despite the static analysis suggesting a high percentage of properly escaped outputs. The fact that these vulnerabilities are documented suggests that while they might be patched at the time of analysis, there's a recurring pattern of security flaws that could be reintroduced in future versions or that the existing sanitization might not be fully robust.

A notable weakness in the static analysis is the complete lack of nonce checks and capability checks for the identified entry points, including the shortcode. While the current version may not have exploitable issues due to other factors or perhaps due to patches applied to address the historical CVEs, this omission creates a potential avenue for attack if the shortcode's functionality becomes more sensitive or if its usage patterns change in the future. The plugin should implement robust authorization checks.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
  • Historical CVEs (2 Medium)
  • Some output not properly escaped
Vulnerabilities
2

Taeggie Feed Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-6382medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Taeggie Feed <= 0.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via name Attribute

Jul 23, 2025 Patched in 0.1.11 (90d)
CVE-2024-11748medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Taeggie Feed <= 0.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 17, 2024 Patched in 0.1.10 (1d)
Code Analysis
Analyzed Mar 16, 2026

Taeggie Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped4 total outputs
Attack Surface

Taeggie Feed Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[taeggie-feed] taeggie_feed.php:78
WordPress Hooks 1
actionwp_enqueue_scriptstaeggie_feed.php:77
Maintenance & Trust

Taeggie Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 30, 2025
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Taeggie Feed Developer Profile

Taeggie

1 plugin · 60 total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
46 days
View full developer profile
Detection Fingerprints

How We Detect Taeggie Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/taeggie-feed/taeggie-feed.php

HTML / DOM Fingerprints

JS Globals
jQuery
Shortcode Output
<iframe src="https://taeggie.com/embed//iframe" scrolling="no" frameborder="0" style="border:none; overflow:hidden; height: 720px; width: 100%;" allowTransparency="true"></iframe><script id="taeggie-feed-widget-script-">jQuery.getScript("
FAQ

Frequently Asked Questions about Taeggie Feed