Widgets for Pinterest Feed Security & Risk Analysis

wordpress.org/plugins/widgets-for-pinterest-feed

Pinterest Feed Widgets. Display your Pinterest feed on your website to increase engagement, sales and SEO.

10 active installs v1.8 PHP 7.0+ WP 6.2+ Updated Mar 19, 2026
feedgalleryphotopinterestwidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Widgets for Pinterest Feed Safe to Use in 2026?

Generally Safe

Score 100/100

Widgets for Pinterest Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "widgets-for-pinterest-feed" plugin v1.7.9 exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent practices regarding SQL query sanitization, with 100% of queries using prepared statements, and robust output escaping, with all 460 outputs properly escaped. The plugin also implements a good number of nonce and capability checks, indicating an awareness of common WordPress security mechanisms. Furthermore, the absence of any known CVEs, past or present, suggests a history of responsible development or effective patching.

However, there are specific areas that warrant attention. The taint analysis revealed 2 flows with unsanitized paths, which, while not flagged as critical or high severity in this analysis, could potentially be exploited if they lead to sensitive operations or external interactions. The presence of external HTTP requests without explicit details about their sanitization or purpose also represents a potential attack vector if the target of these requests is untrusted or if the data sent to them is not properly validated. The overall lack of a significant attack surface (no AJAX handlers, REST API routes, shortcodes, or cron events without checks) is a positive attribute, but the existence of any unsanitized paths, however minor they may appear now, is a point of concern that should be investigated further.

In conclusion, this plugin is well-developed from a security perspective in many areas, particularly concerning data handling and WordPress core security features. The absence of historical vulnerabilities is a strong positive. The primary weaknesses identified are the 2 unsanitized path flows in the taint analysis and the external HTTP requests, which represent potential risks that, while not demonstrably exploited or severe at this moment, require careful consideration and potential mitigation.

Key Concerns

  • Flows with unsanitized paths found
  • External HTTP requests made
Vulnerabilities
None known

Widgets for Pinterest Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Widgets for Pinterest Feed Release Timeline

v1.8Current
v1.7.9
v1.7.8
v1.7.7
v1.7.6
v1.7.5
v1.6.7
Code Analysis
Analyzed Mar 16, 2026

Widgets for Pinterest Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
458 escaped
Nonce Checks
15
Capability Checks
4
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

100% escaped460 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
<admin> (include\admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Widgets for Pinterest Feed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 27
filterrocket_minify_excluded_external_jsinclude\cache-plugin-filters.php:13
filterrocket_exclude_jsinclude\cache-plugin-filters.php:14
filterrocket_delay_js_exclusionsinclude\cache-plugin-filters.php:15
filterlitespeed_optimize_js_excludesinclude\cache-plugin-filters.php:16
filtersgo_javascript_combine_excluded_external_pathsinclude\cache-plugin-filters.php:17
filtersgo_css_combine_excludeinclude\cache-plugin-filters.php:18
filterrocket_rucss_safelistinclude\cache-plugin-filters.php:58
filterscript_loader_taginclude\cache-plugin-filters.php:63
filterstyle_loader_taginclude\cache-plugin-filters.php:78
actionwp_footertrustindex-feed-plugin.class.php:4810
actionadmin_footertrustindex-feed-plugin.class.php:4811
filterfilesystem_methodtrustindex-feed-plugin.class.php:4895
actionadmin_noticestrustindex-feed-plugin.class.php:4920
actionplugins_loadedwidgets-for-pinterest-feed.php:34
actionadmin_menuwidgets-for-pinterest-feed.php:35
filterplugin_action_linkswidgets-for-pinterest-feed.php:36
filterplugin_row_metawidgets-for-pinterest-feed.php:37
actioninitwidgets-for-pinterest-feed.php:38
actionadmin_enqueue_scriptswidgets-for-pinterest-feed.php:39
actioninitwidgets-for-pinterest-feed.php:41
actioninitwidgets-for-pinterest-feed.php:57
filterscript_loader_tagwidgets-for-pinterest-feed.php:58
actionrest_api_initwidgets-for-pinterest-feed.php:64
actionadmin_noticeswidgets-for-pinterest-feed.php:105
actionelementor/widgets/widgets_registeredwidgets-for-pinterest-feed.php:147
actionelementor/elements/categories_registeredwidgets-for-pinterest-feed.php:151
actionwp_enqueue_scriptswidgets-for-pinterest-feed.php:160
Maintenance & Trust

Widgets for Pinterest Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 19, 2026
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Widgets for Pinterest Feed Developer Profile

Trustindex

34 plugins · 975K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
71 days
View full developer profile
Detection Fingerprints

How We Detect Widgets for Pinterest Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/widgets-for-pinterest-feed/assets/css/frontend-notifictions.css/wp-content/plugins/widgets-for-pinterest-feed/assets/js/frontend-notifictions.js
Script Paths
/wp-content/plugins/widgets-for-pinterest-feed/assets/js/frontend-notifictions.js
Version Parameters
widgets-for-pinterest-feed/assets/css/frontend-notifictions.css?ver=widgets-for-pinterest-feed/assets/js/frontend-notifictions.js?ver=

HTML / DOM Fingerprints

CSS Classes
trustindex-notification-rowtrustindex-star-rowti-close-notificationti-remind-laterti-hide-notificationtrustindex-noticetrustindex-notice-dismiss
HTML Comments
Copyright 2019 Trustindex Kft (email: support@trustindex.io)
Data Attributes
data-close-urldata-redirect-url
JS Globals
TRUSTINDEX_Feed_Pinterest
REST Endpoints
/wp-json/widgets-for-pinterest-feed/v1/get-token/wp-json/widgets-for-pinterest-feed/v1/troubleshooting/wp-json/widgets-for-pinterest-feed/v1/refresh-data
FAQ

Frequently Asked Questions about Widgets for Pinterest Feed