
WP Story Security & Risk Analysis
wordpress.org/plugins/wp-storyCreate your own custom Instagram style stories. Show them on any part of your site by adding custom links, text and images.
Is WP Story Safe to Use in 2026?
Generally Safe
Score 85/100WP Story has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-story" plugin v2.1.2 presents a generally strong security posture with several good practices in place. The absence of dangerous functions, file operations, external HTTP requests, and SQL queries that are not prepared statements are all positive indicators. Furthermore, the plugin has no recorded vulnerability history, which suggests a stable and likely secure past.
However, there are specific areas that warrant attention. The static analysis reveals one unprotected REST API route, representing a potential entry point for unauthorized access or manipulation. While the plugin implements nonce and capability checks, the single unprotected REST API endpoint bypasses these crucial security mechanisms, creating a significant concern. The output escaping, while at 72%, still leaves room for potential cross-site scripting (XSS) vulnerabilities if the remaining 28% of outputs are not properly sanitized.
In conclusion, while the plugin demonstrates good foundational security, the unprotected REST API route is a critical flaw that significantly elevates the risk. Addressing this specific vulnerability should be the immediate priority to improve the plugin's overall security. The moderate percentage of unescaped outputs also suggests a need for further code review to ensure all outputs are adequately protected.
Key Concerns
- Unprotected REST API route
- Unescaped output (28%)
WP Story Security Vulnerabilities
WP Story Code Analysis
Output Escaping
Data Flow Analysis
WP Story Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
WP Story Maintenance & Trust
Maintenance Signals
Community Trust
WP Story Alternatives
My Story
my-story
Create your own custom Instagram style stories. ✌
Web Stories
web-stories
Web Stories are a visual storytelling format for the open web which immerses your readers in fast-loading, full-screen, and visually rich experiences.
MakeStories (for Google Web Stories)
makestories-helper
MakeStories helper plugin to publish stories for your WordPress site
EmbedStories – Display social media stories
embedstories
EmbedStories allows you to easily embed Instagram Stories on your website
Web Stories Enhancer – Level Up Your Web Stories
web-stories-enhancer
This is the Web Stories Enhancer Plugin for showing the web stories to the website with the help of a shortcode [web_stories_enhancer].
WP Story Developer Profile
1 plugin · 1K total installs
How We Detect WP Story
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-story/css/selectize.min.css/wp-content/plugins/wp-story/css/wp-story-admin.css/wp-content/plugins/wp-story/js/selectize.min.js/wp-content/plugins/wp-story/js/wp-story-admin.js/wp-content/plugins/wp-story/js/selectize.min.js/wp-content/plugins/wp-story/js/wp-story-admin.jswp-story-admin.css?ver=wp-story-admin.js?ver=HTML / DOM Fingerprints
story-postsname="wp-story_stories[]"id="wp-story_stories"wpStoryObject