
Add to Circle Widget Security & Risk Analysis
wordpress.org/plugins/add-to-circle-widgetThis plugin generates a widget to add Google+ badge on your blog with 'Add to Circles' button.
Is Add to Circle Widget Safe to Use in 2026?
Generally Safe
Score 100/100Add to Circle Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'add-to-circle-widget' v1.0 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no file operations, no external HTTP requests, and all SQL queries utilize prepared statements. Furthermore, there is a complete absence of known vulnerabilities (CVEs) and a history of no recorded issues, which suggests a generally well-maintained codebase.
However, significant concerns arise from the lack of any output escaping. With 18 total outputs, none are properly escaped, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. This deficiency, coupled with the absence of nonces and capability checks, leaves the plugin vulnerable to injection attacks that could be leveraged to execute arbitrary JavaScript in the context of a logged-in user's session, even if no direct entry points like AJAX or REST API endpoints are exposed without authentication. The zero count for taint analysis flows is likely a result of limited analysis or the absence of exploitable flows, but it does not mitigate the risk posed by unescaped output.
In conclusion, while the plugin's foundation appears solid with secure database interactions and a clean vulnerability history, the critical oversight in output sanitization renders it highly susceptible to XSS attacks. This weakness overshadows the strengths and requires immediate attention to prevent potential security breaches.
Key Concerns
- No output escaping
- No nonce checks
- No capability checks
Add to Circle Widget Security Vulnerabilities
Add to Circle Widget Code Analysis
Output Escaping
Add to Circle Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
Add to Circle Widget Maintenance & Trust
Maintenance Signals
Community Trust
Add to Circle Widget Alternatives
Google+ Follow Box
google-plus-badge-like-fb-like-box
Google+ Badge / Follow Box Widget like FB Like Box
Google Plus Badge Direct Connect
google-badge-connect-direct-for-wordpress
Google+ badge allows visitors to directly connect with and promote your brand on Google+ from your website. Now you can add a Google+ badge to help yo …
Google+ Page Badge
google-page-badge
Show one or multiple Google+ badges for your G+ page in a widget, using a shortcode, or with template tags.
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
Add to Circle Widget Developer Profile
1 plugin · 10 total installs
How We Detect Add to Circle Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
https://apis.google.com/js/plusone.jsHTML / DOM Fingerprints
Add_to_Circle_Widgetdata-gapiscan<g:plus href=size=theme=