Atomic Social Kit Security & Risk Analysis

wordpress.org/plugins/atomic-social-kit

Display social media feeds and reviews from Facebook with beautiful Gutenberg blocks.

0 active installs v1.0.0 PHP 7.4+ WP 6.5+ Updated Mar 9, 2026
facebookfeedbackgutenberg-blocksreviewssocial-media
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Atomic Social Kit Safe to Use in 2026?

Generally Safe

Score 100/100

Atomic Social Kit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 26d ago
Risk Assessment

The atomic-social-kit v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output, indicating a solid foundation against common injection and XSS vulnerabilities. The absence of known CVEs and dangerous functions further contributes to its perceived stability. However, significant concerns arise from its attack surface. Two out of three REST API routes lack permission callbacks, creating direct entry points for unauthenticated users. This is a critical oversight that can lead to unauthorized data access or modification, depending on the functionality exposed by these routes. The lack of nonce checks on any AJAX handlers, although there are no AJAX handlers in this version, is a potential future risk if AJAX functionality is added without proper validation. The plugin's vulnerability history is clean, which is reassuring, but this should not overshadow the immediate risks identified in the code analysis.

Key Concerns

  • REST API routes without permission callbacks
  • No nonce checks found
Vulnerabilities
None known

Atomic Social Kit Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Atomic Social Kit Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
42 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

100% escaped42 total outputs
Attack Surface
2 unprotected

Atomic Social Kit Attack Surface

Entry Points3
Unprotected2

REST API Routes 3

GET/wp-json/ask/v1/facebook/feedatomic-social-kit.php:390
GET/wp-json/ask/v1/facebook/reviewsatomic-social-kit.php:397
GET/wp-json/ask/v1/settingsatomic-social-kit.php:404
WordPress Hooks 6
actioninitatomic-social-kit.php:35
actioninitatomic-social-kit.php:36
actionadmin_menuatomic-social-kit.php:37
actionrest_api_initatomic-social-kit.php:38
actionenqueue_block_editor_assetsatomic-social-kit.php:39
filterblock_categories_allatomic-social-kit.php:40
Maintenance & Trust

Atomic Social Kit Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version7.4
Downloads135

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Atomic Social Kit Developer Profile

WP Caliph

4 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Atomic Social Kit

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/atomic-social-kit/build/blocks/facebook-feed/style-index.css/wp-content/plugins/atomic-social-kit/assets/js/facebook-feed-frontend.js/wp-content/plugins/atomic-social-kit/assets/css/swiper-bundle.min.css/wp-content/plugins/atomic-social-kit/assets/js/swiper-bundle.min.js
Script Paths
/wp-content/plugins/atomic-social-kit/assets/js/facebook-feed-frontend.js/wp-content/plugins/atomic-social-kit/assets/js/swiper-bundle.min.js
Version Parameters
atomic-social-kit/build/blocks/facebook-feed/style-index.css?ver=atomic-social-kit/assets/js/facebook-feed-frontend.js?ver=atomic-social-kit/assets/css/swiper-bundle.min.css?ver=atomic-social-kit/assets/js/swiper-bundle.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
ask-loadingask-post-cardask-post-contentask-feed-container
Data Attributes
data-layout-typedata-card-styledata-card-background-colordata-card-border-colordata-card-border-widthdata-card-padding+12 more
JS Globals
atomsokiFeedData
REST Endpoints
/wp-json/ask/v1/
FAQ

Frequently Asked Questions about Atomic Social Kit