
Astra Widgets Security & Risk Analysis
wordpress.org/plugins/astra-widgetsQuickest solution to add widgets like Address, Social Profiles and List icons on a website built with Astra.
Is Astra Widgets Safe to Use in 2026?
Generally Safe
Score 96/100Astra Widgets has a strong security track record. Known vulnerabilities have been patched promptly.
The 'astra-widgets' plugin v1.2.17 exhibits a mixed security posture. On the positive side, the static analysis reveals no identified critical or high-severity taint flows, a very high percentage of properly escaped output, and the use of prepared statements for all SQL queries. The plugin also demonstrates good practices with nonce checks and capability checks, and a limited attack surface in terms of entry points. However, a concerning aspect is the history of three medium-severity vulnerabilities, all related to Cross-Site Scripting (XSS). This pattern suggests a recurring weakness in handling user input that could potentially lead to future exploitable flaws if not addressed rigorously. Despite the current absence of unpatched CVEs and a generally clean static analysis, the past vulnerability history warrants caution.
Key Concerns
- Past medium severity XSS vulnerabilities
Astra Widgets Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Astra Widgets <= 1.2.16 - Authenticated (Editor+) Stored Cross-Site Scripting
Astra Widgets <= 1.2.15 - Authenticated (Contributor+) Stored Cross-Site Scripting
Astra Widgets <= 1.2.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
Astra Widgets Code Analysis
Output Escaping
Astra Widgets Attack Surface
WordPress Hooks 15
Maintenance & Trust
Astra Widgets Maintenance & Trust
Maintenance Signals
Community Trust
Astra Widgets Alternatives
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
Simple Social Icons
simple-social-icons
This plugin provides two ways to display social icons: a traditional widget (available on all WordPress versions) and block variations for the core So …
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Social Media Share Buttons & Social Sharing Icons
ultimate-social-media-icons
Share buttons and pop up share icons for social media sharing
Astra Widgets Developer Profile
32 plugins · 8.6M total installs
How We Detect Astra Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/astra-widgets/admin/bsf-analytics/assets/css/minified/style.min.cssastra-widgets/admin/bsf-analytics/assets/css/minified/style.min.css?ver=HTML / DOM Fingerprints
astra-noticesastra-notices-containernotice-contentnotice-headingdata-repeat-notice-after/wp-json/bsf-core/v1/analytics/