
All-Social FW Style Security & Risk Analysis
wordpress.org/plugins/all-social-fw-style-widgetTodos tus sitios web en un solo widget: Facebook, Twitter, Google Plus y FeedBurner.
Is All-Social FW Style Safe to Use in 2026?
Generally Safe
Score 85/100All-Social FW Style has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "all-social-fw-style-widget" v0.1 exhibits a mixed security posture. On one hand, the static analysis reveals a complete lack of known CVEs and a clean vulnerability history, suggesting a history of diligent security practices or a lack of prior exploitation. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are good indicators of a secure codebase.
However, significant concerns arise from the code signals. The presence of `create_function` is a major red flag, as it is deprecated and can lead to code injection vulnerabilities. Crucially, the analysis shows that 100% of the output is not properly escaped, posing a severe risk for Cross-Site Scripting (XSS) vulnerabilities. While the attack surface appears small with no apparent entry points for AJAX, REST API, shortcodes, or cron events, this could be misleading if the plugin relies on other means to interact with WordPress or external services that are not captured by these static analysis metrics.
In conclusion, the plugin's lack of historical vulnerabilities is a positive sign, but the critical issues identified in the static analysis, particularly the unescaped output and the use of `create_function`, introduce substantial security risks that require immediate attention. The small attack surface is overshadowed by the severe weaknesses in output sanitization and the use of a dangerous function.
Key Concerns
- 100% of outputs are not properly escaped
- Use of dangerous function: create_function
- No nonce checks
- No capability checks
All-Social FW Style Security Vulnerabilities
All-Social FW Style Code Analysis
Dangerous Functions Found
Output Escaping
All-Social FW Style Attack Surface
WordPress Hooks 2
Maintenance & Trust
All-Social FW Style Maintenance & Trust
Maintenance Signals
Community Trust
All-Social FW Style Alternatives
RS Social Sidebar
rs-social-sidebar
Another social plugin :). Difference is the hover effect.
Metro Style Social Widget
metro-style-social-widget
Metro Style Social Network Widget
Jamie Social Icons
jamie-social-icons
Share your posts & pages with your favourite social sites - Twitter, Facebook, Google Plus, Pinterest And LinkedIn and now trackable with your Goo …
Social Media Badge Widget
social-media-badge-widget
This plugin creates a widget which easily displays the social badges from the leading social media websites in a clear an elegant way.
Social Icons Widget
social-icons-widget
A developer-friendly plugin that allows you to add a widget with links to various social media profiles.
All-Social FW Style Developer Profile
1 plugin · 10 total installs
How We Detect All-Social FW Style
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-social-fw-style-widget/wd_all_social.cssHTML / DOM Fingerprints
followcfmyasideinnerboxboxtwittertwitter-follow-buttonc_plusoneboxgplus+3 moredata-lang="es"platform.twitter.com/widgets.js