
10WebSocial Security & Risk Analysis
wordpress.org/plugins/wd-instagram-feed10Web
Is 10WebSocial Safe to Use in 2026?
Mostly Safe
Score 84/10010WebSocial is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The wd-instagram-feed plugin v1.4.35 exhibits a mixed security posture. While a significant majority of SQL queries are prepared (63%) and output escaping is generally well-implemented (97%), there are notable areas of concern. The presence of two AJAX handlers lacking authentication checks represents a direct attack vector. The two known medium severity vulnerabilities, both related to Cross-Site Scripting (XSS), and the fact that the last vulnerability was in late 2021, suggest a history of such issues, even if they are currently patched. The use of 'unserialize' is also a red flag, as it can be dangerous if not handled with extreme care and input validation. While the taint analysis did not reveal critical or high severity issues, the five flows with unsanitized paths warrant attention, as they indicate potential for unintended data manipulation or exposure. Overall, the plugin has some strong security practices in place, but the lack of authentication on certain entry points and the history of XSS vulnerabilities, coupled with the dangerous function usage, present tangible risks that require careful consideration.
Key Concerns
- Unprotected AJAX handlers
- Use of dangerous 'unserialize' function
- Medium severity CVEs in history
- Unsanitized paths in taint flows
10WebSocial Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
10Web Social Photo Feed <= 1.4.28 - Reflected Cross-Site Scripting
WD Instagram Feed <= 1.3.0 - Cross-site scripting
10WebSocial Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
10WebSocial Attack Surface
AJAX Handlers 23
Shortcodes 2
WordPress Hooks 49
Scheduled Events 1
Maintenance & Trust
10WebSocial Maintenance & Trust
Maintenance Signals
Community Trust
10WebSocial Alternatives
No alternatives data available yet.
10WebSocial Developer Profile
9 plugins · 365K total installs
How We Detect 10WebSocial
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wd-instagram-feed/css/wd-instagram-feed.css/wp-content/plugins/wd-instagram-feed/js/wd-instagram-feed.js/wp-content/plugins/wd-instagram-feed/css/wd-instagram-feed-admin.css/wp-content/plugins/wd-instagram-feed/js/wd-instagram-feed-admin.js/wp-content/plugins/wd-instagram-feed/js/block.js/wp-content/plugins/wd-instagram-feed/css/block.css/wp-content/plugins/wd-instagram-feed/css/wdi_frontend.css/wp-content/plugins/wd-instagram-feed/js/wdi_frontend.jswd-instagram-feed/css/wd-instagram-feed.css?ver=wd-instagram-feed/js/wd-instagram-feed.js?ver=wd-instagram-feed/css/wd-instagram-feed-admin.css?ver=wd-instagram-feed/js/wd-instagram-feed-admin.js?ver=wd-instagram-feed/js/block.js?ver=wd-instagram-feed/css/block.css?ver=wd-instagram-feed/css/wdi_frontend.css?ver=wd-instagram-feed/js/wdi_frontend.js?ver=HTML / DOM Fingerprints
wdi_instagram_feed_containerdata-feed-idwdi_frontend_ajax_object/wp-json/wdi/v1/feed/wp-json/wdi/v1/settings