Widgets for Social Post Feed Security & Risk Analysis

wordpress.org/plugins/widgets-for-social-post-feed

Facebook Feed Widgets. Display your Facebook feed on your website to increase engagement, sales and SEO.

300 active installs v1.8 PHP 7.0+ WP 6.2+ Updated Mar 19, 2026
facebookfeedgallerypostswidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Widgets for Social Post Feed Safe to Use in 2026?

Generally Safe

Score 100/100

Widgets for Social Post Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "widgets-for-social-post-feed" plugin v1.7.9 demonstrates a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events directly exposed to potential attackers significantly limits the attack surface. Furthermore, the code exhibits excellent practices regarding SQL query preparation and output escaping, with 100% of both being handled correctly. The plugin also performs a commendable number of nonce and capability checks, indicating an awareness of WordPress security best practices.

However, the taint analysis reveals a potential concern with two identified "flows with unsanitized paths." While rated as not critical or high severity in this specific analysis, un-sanitized paths can be a precursor to more severe vulnerabilities if user-supplied input is not handled with extreme care. The plugin's history of zero known CVEs is a positive indicator, suggesting a stable and secure past. Nonetheless, the presence of unsanitized paths, even if currently of low severity, warrants attention as it represents a deviation from the otherwise robust security measures observed.

In conclusion, the plugin is built on a solid foundation of secure coding practices, particularly in handling database interactions and output. The primary area for improvement lies in thoroughly investigating and sanitizing the identified "flows with unsanitized paths" to eliminate any potential for future exploitation. The lack of historical vulnerabilities is a significant strength, but proactive attention to the current taint analysis findings is crucial for maintaining this strong security record.

Key Concerns

  • Flows with unsanitized paths found
Vulnerabilities
None known

Widgets for Social Post Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Widgets for Social Post Feed Release Timeline

v1.8Current
v1.7.9
v1.7.8
v1.7.7
v1.7.6
v1.7.5
v1.6.7
v1.4.9
v1.3
Code Analysis
Analyzed Mar 16, 2026

Widgets for Social Post Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
458 escaped
Nonce Checks
15
Capability Checks
4
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

100% escaped460 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
<admin> (include\admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Widgets for Social Post Feed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 27
filterrocket_minify_excluded_external_jsinclude\cache-plugin-filters.php:13
filterrocket_exclude_jsinclude\cache-plugin-filters.php:14
filterrocket_delay_js_exclusionsinclude\cache-plugin-filters.php:15
filterlitespeed_optimize_js_excludesinclude\cache-plugin-filters.php:16
filtersgo_javascript_combine_excluded_external_pathsinclude\cache-plugin-filters.php:17
filtersgo_css_combine_excludeinclude\cache-plugin-filters.php:18
filterrocket_rucss_safelistinclude\cache-plugin-filters.php:58
filterscript_loader_taginclude\cache-plugin-filters.php:63
filterstyle_loader_taginclude\cache-plugin-filters.php:78
actionwp_footertrustindex-feed-plugin.class.php:4810
actionadmin_footertrustindex-feed-plugin.class.php:4811
filterfilesystem_methodtrustindex-feed-plugin.class.php:4895
actionadmin_noticestrustindex-feed-plugin.class.php:4920
actionplugins_loadedwidgets-for-social-post-feed.php:34
actionadmin_menuwidgets-for-social-post-feed.php:35
filterplugin_action_linkswidgets-for-social-post-feed.php:36
filterplugin_row_metawidgets-for-social-post-feed.php:37
actioninitwidgets-for-social-post-feed.php:38
actionadmin_enqueue_scriptswidgets-for-social-post-feed.php:39
actioninitwidgets-for-social-post-feed.php:41
actioninitwidgets-for-social-post-feed.php:57
filterscript_loader_tagwidgets-for-social-post-feed.php:58
actionrest_api_initwidgets-for-social-post-feed.php:64
actionadmin_noticeswidgets-for-social-post-feed.php:105
actionelementor/widgets/widgets_registeredwidgets-for-social-post-feed.php:147
actionelementor/elements/categories_registeredwidgets-for-social-post-feed.php:151
actionwp_enqueue_scriptswidgets-for-social-post-feed.php:160
Maintenance & Trust

Widgets for Social Post Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 19, 2026
PHP min version7.0
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs300
Developer Profile

Widgets for Social Post Feed Developer Profile

Trustindex

34 plugins · 975K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
71 days
View full developer profile
Detection Fingerprints

How We Detect Widgets for Social Post Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/widgets-for-social-post-feed/assets/css/frontend-notifictions.css/wp-content/plugins/widgets-for-social-post-feed/assets/js/frontend-notifictions.js
Script Paths
/wp-content/plugins/widgets-for-social-post-feed/trustindex-feed-plugin.class.php/wp-content/plugins/widgets-for-social-post-feed/include/cache-plugin-filters.php/wp-content/plugins/widgets-for-social-post-feed/include/trustindex-elementor-widgets.php
Version Parameters
widgets-for-social-post-feed/style.css?ver=widgets-for-social-post-feed/assets/css/frontend-notifictions.css?ver=widgets-for-social-post-feed/assets/js/frontend-notifictions.js?ver=

HTML / DOM Fingerprints

CSS Classes
trustindex-notification-rowtrustindex-star-rowti-close-notificationti-button-primaryti-remind-laterti-hide-notificationtrustindex-noticetrustindex-notice-dismiss
HTML Comments
Copyright 2019 Trustindex Kft (email: support@trustindex.io)You should have received a copy of the GNU General Public License along with Review widget addon for Divi. If not, see https://www.gnu.org/licenses/gpl-2.0.html.
Data Attributes
data-close-urldata-redirect-url
JS Globals
TRUSTINDEX_Feed_Facebook
REST Endpoints
/wp-json/widgets-for-social-post-feed/v1/get-token/wp-json/widgets-for-social-post-feed/v1/troubleshooting/wp-json/widgets-for-social-post-feed/v1/refresh-data
FAQ

Frequently Asked Questions about Widgets for Social Post Feed