Gallery Feed for TikTok – Show TikTok Videos in Grid, Masonry, or Slideshow Security & Risk Analysis

wordpress.org/plugins/ws-tiktok-feed

Embed TikTok videos and feeds in WordPress. Show likes, views, comments, shares & user info with Grid, Blog, Masonry, or Slideshow layouts.

30 active installs v1.2.5 PHP 7.4+ WP 5.7+ Updated Oct 7, 2025
embed-tiktoktiktoktiktok-feedtiktok-gallerytiktok-video
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gallery Feed for TikTok – Show TikTok Videos in Grid, Masonry, or Slideshow Safe to Use in 2026?

Generally Safe

Score 100/100

Gallery Feed for TikTok – Show TikTok Videos in Grid, Masonry, or Slideshow has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The 'ws-tiktok-feed' plugin v1.2.5 exhibits a mixed security posture. On the positive side, it demonstrates strong practices in terms of SQL query preparation (88%) and output escaping (97%), and has no recorded vulnerability history. This suggests a development team that is aware of common web vulnerabilities and has implemented defenses in key areas.

However, there are significant concerns regarding the plugin's attack surface and authorization. The static analysis reveals 5 entry points, with 3 of them being unprotected. Specifically, 2 out of 3 AJAX handlers lack authentication checks, and 1 out of 1 REST API routes lacks permission callbacks. Furthermore, the taint analysis indicates 2 flows with unsanitized paths, both classified as high severity, which is a critical red flag. These unsanitized paths in combination with unprotected entry points could lead to serious security breaches.

The absence of any known CVEs is positive but does not negate the immediate risks identified in the code analysis. The focus on input validation and sanitization is crucial, and the identified high severity taint flows are the most pressing issues. While the plugin has strengths in certain areas, the current state of its unprotected entry points and unsanitized data flows presents a considerable risk that needs immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Unprotected REST API routes
  • High severity taint flows
  • Lack of capability checks
Vulnerabilities
None known

Gallery Feed for TikTok – Show TikTok Videos in Grid, Masonry, or Slideshow Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gallery Feed for TikTok – Show TikTok Videos in Grid, Masonry, or Slideshow Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
37 prepared
Unescaped Output
9
287 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

88% prepared42 total queries

Output Escaping

97% escaped296 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
tkf_save_feed (admin\controllers\Feeds.php:61)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Gallery Feed for TikTok – Show TikTok Videos in Grid, Masonry, or Slideshow Attack Surface

Entry Points5
Unprotected3

AJAX Handlers 3

authwp_ajax_update_videos_tkftiktok_feed.php:95
noprivwp_ajax_update_videos_tkftiktok_feed.php:96
authwp_ajax_tkf_send_deactivation_reasontiktok_feed.php:99

REST API Routes 1

POST/wp-json/tkf/v1/store-tokenlibrary\TikTokApiClient.php:11

Shortcodes 1

[tkf_feed] tiktok_feed.php:87
WordPress Hooks 9
actionrest_api_initlibrary\TikTokApiClient.php:10
actioninittiktok_feed.php:76
actionadmin_inittiktok_feed.php:77
actionadmin_menutiktok_feed.php:78
actionwp_enqueue_scriptstiktok_feed.php:89
actionadmin_enqueue_scriptstiktok_feed.php:90
actionwp_enqueue_scriptstiktok_feed.php:92
actionadmin_enqueue_scriptstiktok_feed.php:93
actioncurrent_screentiktok_feed.php:100
Maintenance & Trust

Gallery Feed for TikTok – Show TikTok Videos in Grid, Masonry, or Slideshow Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 7, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

Gallery Feed for TikTok – Show TikTok Videos in Grid, Masonry, or Slideshow Developer Profile

WebSync Team

2 plugins · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gallery Feed for TikTok – Show TikTok Videos in Grid, Masonry, or Slideshow

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ws-tiktok-feed/assets/images/menu_icon.png/wp-content/plugins/ws-tiktok-feed/assets/js/tkf_share.js
Script Paths
/wp-content/plugins/ws-tiktok-feed/library/TKFLibrary.js/wp-content/plugins/ws-tiktok-feed/assets/js/tkf_share.js
Version Parameters
ws-tiktok-feed/assets/js/tkf_share.js?ver=ws-tiktok-feed/assets/css/tkf_frontend.css?ver=

HTML / DOM Fingerprints

CSS Classes
tkf_containertkf_single_feedtkf_grid_feedtkf_item_wraptkf_itemtkf_item_videotkf_item_metatkf_item_meta_title+9 more
HTML Comments
<!-- TKF FEEDS START --><!-- TKF FEEDS END -->
Data Attributes
data-tkf-iddata-tkf-feed-id
JS Globals
tkf_shared_obj
Shortcode Output
[tkf_feed
FAQ

Frequently Asked Questions about Gallery Feed for TikTok – Show TikTok Videos in Grid, Masonry, or Slideshow