
Web Stories Enhancer – Level Up Your Web Stories Security & Risk Analysis
wordpress.org/plugins/web-stories-enhancerThis is the Web Stories Enhancer Plugin for showing the web stories to the website with the help of a shortcode [web_stories_enhancer].
Is Web Stories Enhancer – Level Up Your Web Stories Safe to Use in 2026?
Generally Safe
Score 91/100Web Stories Enhancer – Level Up Your Web Stories has a strong security track record. Known vulnerabilities have been patched promptly.
The web-stories-enhancer plugin version 1.4 presents a mixed security posture. On the positive side, the plugin has a relatively small attack surface with no identified REST API routes or cron events, and all identified entry points (AJAX handlers and shortcodes) appear to have some level of protection, as indicated by the absence of unprotected entry points. Furthermore, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are good security practices. The lack of dangerous functions is also a positive sign.
However, there are notable concerns. A significant portion (37%) of output is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if malicious input is not handled correctly. The taint analysis revealed one flow with unsanitized paths, which, while not rated as critical or high severity in this analysis, warrants attention as it indicates a potential for issues if input isn't thoroughly validated. The plugin's vulnerability history shows a past medium-severity CVE related to XSS, suggesting a recurring pattern of input sanitization weaknesses.
In conclusion, while the plugin demonstrates good practices in areas like SQL sanitization and limiting its attack surface, the unescaped output and the presence of an unsanitized path in the taint analysis, coupled with past XSS vulnerabilities, indicate areas that require improvement to strengthen its overall security. The absence of capability checks on entry points is also a potential weakness.
Key Concerns
- Unescaped output detected
- Taint flow with unsanitized paths
- Past medium severity CVE (XSS)
- No capability checks on entry points
Web Stories Enhancer – Level Up Your Web Stories Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Web Stories Enhancer – Level Up Your Web Stories <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Web Stories Enhancer – Level Up Your Web Stories Code Analysis
Output Escaping
Data Flow Analysis
Web Stories Enhancer – Level Up Your Web Stories Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Web Stories Enhancer – Level Up Your Web Stories Maintenance & Trust
Maintenance Signals
Community Trust
Web Stories Enhancer – Level Up Your Web Stories Alternatives
Web Stories
web-stories
Web Stories are a visual storytelling format for the open web which immerses your readers in fast-loading, full-screen, and visually rich experiences.
Web Stories Widgets For Elementor
shortcodes-for-amp-web-stories-and-elementor-widget
This addon will helps you to easily represent Google Web stories in the Page/Post using Elementor Widget and shortcodes.
ZMOOZ Web Stories
zmooz-stories
ZMOOZ Stories is a solution that allows publishers and bloggers to automatically transform their articles into Web Story format.
MakeStories (for Google Web Stories)
makestories-helper
MakeStories helper plugin to publish stories for your WordPress site
Pixel & tracking codes for Google Web stories (formerly AMP Stories)
pixel-for-web-stories
Pixel for Web Stories (Google) allows you to (re)add easily your tracking codes |Pixel (Facebook, Linkedin, Pinterest, Tiktok, Twitter, Yandex, Snapc …
Web Stories Enhancer – Level Up Your Web Stories Developer Profile
13 plugins · 739K total installs
How We Detect Web Stories Enhancer – Level Up Your Web Stories
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/web-stories-enhancer/assets/css/wse-admin.css/wp-content/plugins/web-stories-enhancer/assets/js/wse-admin.js/wp-content/plugins/web-stories-enhancer/assets/js/wse-admin.jsweb-stories-enhancer/assets/css/wse-admin.css?ver=web-stories-enhancer/assets/js/wse-admin.js?ver=HTML / DOM Fingerprints
wse_script_vars[web_stories_enhancer]