AtticThemes: Social Icons Security & Risk Analysis

wordpress.org/plugins/atticthemes-social-icons

Add social icons anywhere in posts, pages and custom post types with a convenient and user friendly UI.

70 active installs v2.1.2 PHP + WP 4.0.0+ Updated Oct 15, 2016
iconssocial
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is AtticThemes: Social Icons Safe to Use in 2026?

Generally Safe

Score 85/100

AtticThemes: Social Icons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "atticthemes-social-icons" plugin v2.1.2 exhibits a generally good security posture based on the provided static analysis. The plugin has a limited attack surface, with only two AJAX handlers and no exposed REST API routes, shortcodes, or cron events. Crucially, all identified entry points appear to have authentication checks, which is a significant strength. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and including nonce checks for its entry points.

However, there are areas for improvement. The most notable concern is the low percentage of properly escaped output (23%). This suggests a significant risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data, if not properly sanitized before being displayed, could be injected into the page and executed by a user's browser. Taint analysis did not reveal any unsanitized paths or critical/high severity flows, which is positive, but this could be a consequence of the limited analysis scope or the lack of complex data handling in the plugin.

Furthermore, the absence of any recorded vulnerabilities in its history (CVEs or otherwise) is excellent. This could indicate diligent development and maintenance, or it might simply mean the plugin hasn't been a target or extensively audited. Despite the strong points in input validation and SQL practices, the poor output escaping is a critical weakness that needs immediate attention to prevent potential XSS attacks.

Key Concerns

  • Low output escaping rate (23%)
Vulnerabilities
None known

AtticThemes: Social Icons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AtticThemes: Social Icons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
6 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

23% escaped26 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
saveSet (atticthemes-social-icons.php:479)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AtticThemes: Social Icons Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_atticthemes_social_icon_save_setatticthemes-social-icons.php:171
authwp_ajax_atticthemes_social_icon_increment_idsatticthemes-social-icons.php:172
WordPress Hooks 6
actionadmin_initatticthemes-social-icons.php:174
actionadmin_menuatticthemes-social-icons.php:175
actionadmin_enqueue_scriptsatticthemes-social-icons.php:178
actionwp_enqueue_scriptsatticthemes-social-icons.php:181
filterwidget_textatticthemes-social-icons.php:215
actionafter_setup_themeatticthemes-social-icons.php:542
Maintenance & Trust

AtticThemes: Social Icons Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedOct 15, 2016
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs70
Developer Profile

AtticThemes: Social Icons Developer Profile

AtticThemes

3 plugins · 90 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AtticThemes: Social Icons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/atticthemes-social-icons/css/admin/font-awesome.min.css/wp-content/plugins/atticthemes-social-icons/css/admin/social-icons-admin.css/wp-content/plugins/atticthemes-social-icons/css/social-icons.css/wp-content/plugins/atticthemes-social-icons/js/admin/social-icons-admin.js/wp-content/plugins/atticthemes-social-icons/js/social-icons.js
Script Paths
/wp-content/plugins/atticthemes-social-icons/js/admin/social-icons-admin.js/wp-content/plugins/atticthemes-social-icons/js/social-icons.js
Version Parameters
atticthemes-social-icons/css/admin/font-awesome.min.css?ver=atticthemes-social-icons/css/admin/social-icons-admin.css?ver=atticthemes-social-icons/css/social-icons.css?ver=atticthemes-social-icons/js/admin/social-icons-admin.js?ver=atticthemes-social-icons/js/social-icons.js?ver=

HTML / DOM Fingerprints

CSS Classes
atsi-iconatsi-social-iconsocial-iconsocial-icons-wrappericon-set-titleicon-set-controlsicon-set-addicon-set-edit+5 more
Data Attributes
data-iconsetdata-icondata-link
JS Globals
atticthemes_social
Shortcode Output
[atsi][atsi id="" size=""]
FAQ

Frequently Asked Questions about AtticThemes: Social Icons