Taggbox: Social Feed Widgets Security & Risk Analysis

wordpress.org/plugins/taggbox-widget

Collect, Curate & Publish Instagram, Facebook Feeds, YouTube Videos, Twitter (X) Feeds, Google Reviews & 20+ Social Media Widgets on your website.

1K active installs v3.8 PHP 5.6+ WP 3.0+ Updated Mar 6, 2026
facebookgoogle-reviewsinstagramlinkedintwitter
94
A · Safe
CVEs total5
Unpatched0
Last CVEJul 11, 2024
Safety Verdict

Is Taggbox: Social Feed Widgets Safe to Use in 2026?

Generally Safe

Score 94/100

Taggbox: Social Feed Widgets has a strong security track record. Known vulnerabilities have been patched promptly.

5 known CVEsLast CVE: Jul 11, 2024Updated 28d ago
Risk Assessment

The "taggbox-widget" plugin version 3.9 demonstrates some positive security practices, including the use of prepared statements for all SQL queries and a high percentage of properly escaped output. However, the vulnerability history is a significant concern, with a total of 5 known CVEs, including one critical and four medium vulnerabilities. The recent discovery of these vulnerabilities suggests a recurring pattern of security flaws, with common types including CSRF, XSS, deserialization, and missing authorization. This historical context, coupled with the presence of 3 high-severity taint flows with unsanitized paths despite the limited attack surface, indicates potential weaknesses in input validation and sanitization that could be exploited if not properly addressed.

While the current version has 0 unpatched CVEs and the static analysis shows no unprotected entry points, the historical trend and the identified taint flows warrant caution. The plugin has a history of introducing vulnerabilities that require patching, and the presence of unsanitized paths in the taint analysis, even if not reaching a critical level in this specific version's static scan, points to potential underlying architectural issues. Therefore, while the plugin exhibits some good practices, the past vulnerability record and the specific taint analysis findings suggest a moderate to high risk, especially if future updates do not comprehensively address the root causes of historical vulnerabilities.

Key Concerns

  • 3 high severity taint flows with unsanitized paths
  • 5 total known CVEs (1 critical, 4 medium)
  • History of common vulnerability types
Vulnerabilities
5

Taggbox: Social Feed Widgets Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
3 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Critical
1
Medium
4

5 total CVEs

CVE-2024-38754medium · 4.3Cross-Site Request Forgery (CSRF)

Taggbox <= 3.3 - Cross-Site Request Forgery

Jul 11, 2024 Patched in 3.4 (596d)
CVE-2024-32552medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics <= 3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 16, 2024 Patched in 3.3 (10d)
CVE-2023-52225critical · 9.8Deserialization of Untrusted Data

Taggbox <= 3.1 - Unauthenticated PHP Object Injection

Jan 5, 2024 Patched in 3.2 (784d)
CVE-2023-33215medium · 5.4Missing Authorization

Taggbox <= 3.3 - Missing Authorization

Oct 19, 2023 Patched in 3.4 (862d)
CVE-2023-33214medium · 4.3Cross-Site Request Forgery (CSRF)

Taggbox <= 3.3 - Cross-Site Request Forgery

Oct 12, 2023 Patched in 3.4 (869d)
Code Analysis
Analyzed Mar 16, 2026

Taggbox: Social Feed Widgets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
55 prepared
Unescaped Output
3
250 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared55 total queries

Output Escaping

99% escaped253 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
taggbox_data_ajax_handler (taggbox.php:140)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Taggbox: Social Feed Widgets Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_taggbox_datataggbox.php:139

Shortcodes 1

[taggbox] taggbox.php:1639
WordPress Hooks 7
actioninittaggbox.php:67
filterscript_loader_tagtaggbox.php:68
actionadmin_menutaggbox.php:107
actionactivated_plugintaggbox.php:1510
actionupgrader_process_completetaggbox.php:1554
actionin_admin_headertaggbox.php:1621
actionadmin_noticestaggbox.php:1634
Maintenance & Trust

Taggbox: Social Feed Widgets Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 6, 2026
PHP min version5.6
Downloads37K

Community Trust

Rating100/100
Number of ratings2
Active installs1K
Developer Profile

Taggbox: Social Feed Widgets Developer Profile

Taggbox

1 plugin · 1K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
624 days
View full developer profile
Detection Fingerprints

How We Detect Taggbox: Social Feed Widgets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Taggbox: Social Feed Widgets