AM Social Widget Security & Risk Analysis

wordpress.org/plugins/am-social-widget

AM Social Widget is a plugin that adds very light weight social widget to your appearance->widgets screen. User can set link to their social profil …

0 active installs v1.0.1 PHP 5.2.4+ WP 5.0.3+ Updated Feb 17, 2019
profilessharingsocialsocial-mediawidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AM Social Widget Safe to Use in 2026?

Generally Safe

Score 85/100

AM Social Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "am-social-widget" plugin v1.0.1 exhibits a generally strong security posture based on the provided static analysis. The complete absence of detected entry points like AJAX handlers, REST API routes, shortcodes, and cron events, especially without any authentication checks, is a significant positive indicator. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests further contributes to a reduced attack surface. The use of prepared statements for all SQL queries is commendable and mitigates a common category of vulnerabilities.

However, the analysis reveals a critical weakness in output escaping, with only 35% of outputs being properly escaped. This represents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as unsanitized output can be exploited by attackers to inject malicious scripts into web pages. The lack of nonce checks and capability checks, while potentially mitigated by the zero attack surface, still represents a missed opportunity to reinforce security on any potential future entry points. The plugin also has no recorded vulnerability history, which is positive, but this could also indicate a lack of extensive security auditing rather than a proven track record of security. Overall, while the plugin avoids many common pitfalls, the significant unescaped output presents a clear and present danger.

Key Concerns

  • Low output escaping rate
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

AM Social Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

AM Social Widget Release Timeline

v1.0.1Current
Code Analysis
Analyzed Mar 17, 2026

AM Social Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

35% escaped17 total outputs
Attack Surface

AM Social Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptsam-social-widget.php:51
actionwidgets_initam-social-widget.php:239
Maintenance & Trust

AM Social Widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedFeb 17, 2019
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AM Social Widget Developer Profile

Aamer Shahzad

3 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AM Social Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/am-social-widget/assets/css/style.min.css

HTML / DOM Fingerprints

CSS Classes
am-social-profiles-wrap
Data Attributes
id="am-social-widget"name="am-social-widget"
FAQ

Frequently Asked Questions about AM Social Widget