shouldiuse.io

Categories

VERDICT

Should I use Tagembed?

Social media feeds and customer reviews widget for websites - tagembed.com

Depends. Buy it if you want a cheap, no-code widget showing social feeds and reviews on a Shopify, Webflow, or fully-patched WordPress site. Skip it if your site is security-sensitive or you won't stay on top of plugin updates.

Confidence

Medium. Based on 13 public sources; some user quotes truncated in source snippets.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityOnly vendor-claimed; no independent evidence
  • Security posture

Pricing

$0

Free

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
PlusPaid (not shown in sources)

Best for

  • Small stores showcasing reviews
  • Marketers embedding Instagram/social walls
  • WordPress, Shopify, Webflow site owners

Not for

  • Old or unpatched WordPress installs
  • Security-sensitive or regulated sites
  • Guess: Enterprises needing SSO, SLAs, compliance docs

Gotchas - check before you buy

high

Unauthenticated stored XSS affects plugin ≤7.4; update to 7.5+ immediately or risk site compromise.

high

Missing authorization flaw (CVE-2024-34804) hits versions below 5.9; stale installs stay exposed.

medium

Free plan has functional limits; key capabilities sit behind the paid Plus tier.

medium

Vendor is tiny (~$905K est. revenue); expect limited SLAs and support depth.

Pros and cons

Pros

  • Free plan available for social media feeds
  • Aggregates Instagram, Facebook, Reddit, Google reviews in widgets
  • Collects and displays product reviews via Shopify app
  • Native integrations for WordPress, Shopify, Webflow, Weebly
  • Shoppable Instagram galleries turn feeds into sales

Cons

  • Unauthenticated XSS and authorization CVEs in its WordPress plugin
  • Free plan limits push real usage into paid tiers
  • Monthly subscription pricing on a small widget
  • Small vendor (~$905K est. revenue); longevity risk
  • Mixed word-of-mouth; some SEO practitioners steer others away

Sources & method

Analyzed 10/01/2026 - 13 sources - Multiple WordPress plugin CVEs since 2024, including unauthenticated stored XSS — patch to ≥7.5 before trusting it.

official x4review x4security x3news x2
  • Unauthenticated Stored Cross-Site Scripting (plugin ≤7.4), Unauthenticated attackers can inject scripts via the Tagembed WordPress widget; fixed in 7.5.
  • CVE-2024-34804 — Missing Authorization (plugin <5.9), Plugin failed authorization checks, enabling unauthorized actions; patched in 5.9.
  • CVE-2024-32561 — Improper Neutralization, Input-neutralization vulnerability disclosed April 18, 2024.
  • CVE-2026-66590 — Unauthenticated XSS (plugin ≤7.4), Unauthenticated cross-site scripting listed in CISA and vulnerability databases.

Key stats

  • Value for money: 4/5

    Rating

  • $0

    Starting price

  • 13

    Sources

  • Analyzed

  • Value for money: 4/5. Free tier plus low-cost paid plans
  • Ease of use: 4/5. No-code embeds across major site builders
  • Feature depth: 4/5. Feeds, reviews, shoppable galleries, API
  • Support quality. Only vendor-claimed; no independent evidence
  • Security posture: 2/5. Three plugin CVEs since 2024
  • 4,789+ Websites using it tracked by Tomba
  • Yes Free tier Free-to-Plus pricing model
  • 3 Known CVEs WordPress plugin, 2024–2026
  • $905.3K Est. annual revenue Crunchbase estimate

Pricing

Free

$0

  • Social media feed aggregation
  • Basic review widgets
  • Free-plan limits apply

Plus

Paid (not shown in sources)

  • Higher limits than Free
  • Advanced customization

Security

Multiple WordPress plugin CVEs since 2024, including unauthenticated stored XSS — patch to ≥7.5 before trusting it.

  • Unauthenticated Stored Cross-Site Scripting (plugin ≤7.4)Unauthenticated attackers can inject scripts via the Tagembed WordPress widget; fixed in 7.5.⁵
  • CVE-2024-34804 — Missing Authorization (plugin <5.9)Plugin failed authorization checks, enabling unauthorized actions; patched in 5.9.⁷
  • CVE-2024-32561 — Improper NeutralizationInput-neutralization vulnerability disclosed April 18, 2024.⁶
  • CVE-2026-66590 — Unauthenticated XSS (plugin ≤7.4)Unauthenticated cross-site scripting listed in CISA and vulnerability databases.

What users say

User feedback in sources is sparse: some users say it eases embedding where Trustpilot frustrates, while some SEO practitioners warn others off for Google reviews.

“#Tagembed eases your whole #embedding”
Facebook group post
“Google reviews widget - NOT for…”
Facebook, Local SEO Club group
Full analysis

Based on 13 public sources; some user quotes truncated in source snippets.

Cheap, easy social-proof widgets for small sites — but 3 WordPress CVEs since 2024 mean patch or pass.

Methodology

Based on 13 public sources; some user quotes truncated in source snippets.

Sources

  1. Tagembed homepagetagembed.com
    official
  2. official
  3. official
  4. Tagembed Shopify appapps.shopify.com
    official
  5. security
  6. security
  7. security
  8. review
  9. news
  10. news
  11. review
  12. review
  13. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.