Widgets for Google Feed Security & Risk Analysis

wordpress.org/plugins/widgets-for-google-feed

Google Feed Widgets. Display your Google feed on your website to increase engagement, sales and SEO.

0 active installs v1.8 PHP 7.0+ WP 6.2+ Updated Mar 19, 2026
feedgallerygooglepostswidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Widgets for Google Feed Safe to Use in 2026?

Generally Safe

Score 100/100

Widgets for Google Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "widgets-for-google-feed" plugin v1.7.9 exhibits a generally strong security posture based on the static analysis results. The plugin demonstrates excellent adherence to secure coding practices, with 100% of SQL queries using prepared statements and all outputs being properly escaped. The absence of dangerous functions, file operations, and a clean vulnerability history further contribute to its security. However, there are a couple of areas that warrant attention. The presence of two flows with unsanitized paths in the taint analysis, even without critical or high severity, suggests potential for unintended behavior or exploitation if malicious input is not handled carefully. Additionally, the plugin makes six external HTTP requests, which could be a vector for certain types of attacks (e.g., SSRF) if not implemented with robust validation and error handling.

While the plugin has no recorded vulnerabilities or CVEs, which is a significant positive, the identified unsanitized paths in the taint analysis should not be overlooked. These could represent a weakness that has not yet been exploited or discovered. The plugin's lack of a large attack surface is commendable, but the external requests introduce a degree of risk. Overall, the plugin is well-coded with good security fundamentals, but the identified taint flow issues and external requests should be monitored and potentially addressed to further harden its security.

Key Concerns

  • Flows with unsanitized paths found
  • External HTTP requests made
Vulnerabilities
None known

Widgets for Google Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Widgets for Google Feed Release Timeline

v1.8Current
v1.7.9
v1.7.8
v1.7.7
v1.7.6
v1.7.5
v1.6.7
Code Analysis
Analyzed Mar 17, 2026

Widgets for Google Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
458 escaped
Nonce Checks
15
Capability Checks
4
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

100% escaped460 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
<admin> (include\admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Widgets for Google Feed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 27
filterrocket_minify_excluded_external_jsinclude\cache-plugin-filters.php:13
filterrocket_exclude_jsinclude\cache-plugin-filters.php:14
filterrocket_delay_js_exclusionsinclude\cache-plugin-filters.php:15
filterlitespeed_optimize_js_excludesinclude\cache-plugin-filters.php:16
filtersgo_javascript_combine_excluded_external_pathsinclude\cache-plugin-filters.php:17
filtersgo_css_combine_excludeinclude\cache-plugin-filters.php:18
filterrocket_rucss_safelistinclude\cache-plugin-filters.php:58
filterscript_loader_taginclude\cache-plugin-filters.php:63
filterstyle_loader_taginclude\cache-plugin-filters.php:78
actionwp_footertrustindex-feed-plugin.class.php:4810
actionadmin_footertrustindex-feed-plugin.class.php:4811
filterfilesystem_methodtrustindex-feed-plugin.class.php:4895
actionadmin_noticestrustindex-feed-plugin.class.php:4920
actionplugins_loadedwidgets-for-google-feed.php:34
actionadmin_menuwidgets-for-google-feed.php:35
filterplugin_action_linkswidgets-for-google-feed.php:36
filterplugin_row_metawidgets-for-google-feed.php:37
actioninitwidgets-for-google-feed.php:38
actionadmin_enqueue_scriptswidgets-for-google-feed.php:39
actioninitwidgets-for-google-feed.php:41
actioninitwidgets-for-google-feed.php:57
filterscript_loader_tagwidgets-for-google-feed.php:58
actionrest_api_initwidgets-for-google-feed.php:64
actionadmin_noticeswidgets-for-google-feed.php:105
actionelementor/widgets/widgets_registeredwidgets-for-google-feed.php:147
actionelementor/elements/categories_registeredwidgets-for-google-feed.php:151
actionwp_enqueue_scriptswidgets-for-google-feed.php:160
Maintenance & Trust

Widgets for Google Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 19, 2026
PHP min version7.0
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Widgets for Google Feed Developer Profile

Trustindex

34 plugins · 975K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
71 days
View full developer profile
Detection Fingerprints

How We Detect Widgets for Google Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/widgets-for-google-feed/assets/css/frontend-notifictions.css/wp-content/plugins/widgets-for-google-feed/assets/js/frontend-notifictions.js
Script Paths
/wp-content/plugins/widgets-for-google-feed/trustindex-feed-plugin.class.php
Version Parameters
widgets-for-google-feed/style.css?ver=widgets-for-google-feed/assets/js/frontend-notifictions.js?ver=widgets-for-google-feed/assets/css/frontend-notifictions.css?ver=

HTML / DOM Fingerprints

CSS Classes
trustindex-notification-rowtrustindex-star-rowti-close-notificationti-button-primaryti-remind-laterti-hide-notificationtrustindex-noticetrustindex-notice-dismiss
Data Attributes
data-close-urldata-redirect-url
REST Endpoints
/wp-json/widgets-for-google-feed/v1/get-token/wp-json/widgets-for-google-feed/v1/troubleshooting/wp-json/widgets-for-google-feed/v1/refresh-data
FAQ

Frequently Asked Questions about Widgets for Google Feed