Plugin inspection: Instant Articles

Use with caution

Last revised:

Confidence: Medium
This plugin has been given a short, targeted code review.

Before using this plugin, you should carefully consider these findings. Read more about this recommendation.


This recommendation applies to version 0.8.7 of this plugin, but the most recent version is 0.9.1. These findings may no longer be correct.


  • Allows users with permission to edit settings to insert unfiltered HTML into the admin area settings – i.e. Settings > Instant Articles > Feed. Insert ‘”onclick=”alert(1)’ into the “Number of Articles” field

Reason for the 'Use with caution' result

The plugin contains or is likely to contain a vulnerability which could be exploited by a privileged user to affect the site’s confidentiality, integrity or availability in a manner exceeding their privileges:

Allows admins to insert unfiltered HTML in to the settings fields

Failure criteria

  • Lack of proper output escaping

Read more about our failure criteria.