
Taggbox: Social Feed Widgets Security & Risk Analysis
wordpress.org/plugins/taggbox-widgetCollect, Curate & Publish Instagram, Facebook Feeds, YouTube Videos, Twitter (X) Feeds, Google Reviews & 20+ Social Media Widgets on your website.
Is Taggbox: Social Feed Widgets Safe to Use in 2026?
Generally Safe
Score 94/100Taggbox: Social Feed Widgets has a strong security track record. Known vulnerabilities have been patched promptly.
The "taggbox-widget" plugin version 3.9 demonstrates some positive security practices, including the use of prepared statements for all SQL queries and a high percentage of properly escaped output. However, the vulnerability history is a significant concern, with a total of 5 known CVEs, including one critical and four medium vulnerabilities. The recent discovery of these vulnerabilities suggests a recurring pattern of security flaws, with common types including CSRF, XSS, deserialization, and missing authorization. This historical context, coupled with the presence of 3 high-severity taint flows with unsanitized paths despite the limited attack surface, indicates potential weaknesses in input validation and sanitization that could be exploited if not properly addressed.
While the current version has 0 unpatched CVEs and the static analysis shows no unprotected entry points, the historical trend and the identified taint flows warrant caution. The plugin has a history of introducing vulnerabilities that require patching, and the presence of unsanitized paths in the taint analysis, even if not reaching a critical level in this specific version's static scan, points to potential underlying architectural issues. Therefore, while the plugin exhibits some good practices, the past vulnerability record and the specific taint analysis findings suggest a moderate to high risk, especially if future updates do not comprehensively address the root causes of historical vulnerabilities.
Key Concerns
- 3 high severity taint flows with unsanitized paths
- 5 total known CVEs (1 critical, 4 medium)
- History of common vulnerability types
Taggbox: Social Feed Widgets Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Taggbox <= 3.3 - Cross-Site Request Forgery
Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics <= 3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Taggbox <= 3.1 - Unauthenticated PHP Object Injection
Taggbox <= 3.3 - Missing Authorization
Taggbox <= 3.3 - Cross-Site Request Forgery
Taggbox: Social Feed Widgets Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Taggbox: Social Feed Widgets Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Taggbox: Social Feed Widgets Maintenance & Trust
Maintenance Signals
Community Trust
Taggbox: Social Feed Widgets Alternatives
Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds
tagembed-widget
Collect & Embed Instagram Feed, Embed Facebook Feed, Embed YouTube Videos, Embed Twitter Feed, Google Reviews & 15+ Social Media Feed on website.
LITTLE Social
little-social
Display posts from multiple social media channels and profiles in one combined feed.
Social Media Widget
social-media-widget
Adds links to all of your social media and sharing site profiles. Tons of icons come in 3 sizes, 4 icon styles, and 4 animations.
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)
miniorange-login-openid
Social Login with Discord, Facebook, Google, Twitter, LinkedIn and 40+ apps. Social login with social share and comments. Free, fast & easy! WooCo …
Social Media Auto Publish
social-media-auto-publish
Publish posts automatically to social media networks like Facebook, Twitter, Instagram, Tumblr, LinkedIn, Threads and Telegram.
Taggbox: Social Feed Widgets Developer Profile
1 plugin · 1K total installs
How We Detect Taggbox: Social Feed Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.