AVIR Social Auto Poster Ultimate Security & Risk Analysis

wordpress.org/plugins/avir-social-auto-poster-ultimate

Automatically share WordPress posts to Facebook & Instagram with customizable excerpts, images, and hashtags. Boost your social reach!

40 active installs v1.21 PHP 7.0+ WP 5.0+ Updated Jul 24, 2025
auto-publishfacebook-auto-postinstagram-auto-postsocial-media-automationsocial-share
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AVIR Social Auto Poster Ultimate Safe to Use in 2026?

Generally Safe

Score 100/100

AVIR Social Auto Poster Ultimate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "avir-social-auto-poster-ultimate" v1.21 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices by utilizing prepared statements for all SQL queries, implementing a significant number of nonce and capability checks for its AJAX handlers, and properly escaping a majority of its output. The absence of known CVEs in its history further contributes to a positive security impression, suggesting a history of responsible development and maintenance.

However, a closer examination reveals potential areas of concern. The taint analysis identified one flow with an unsanitized path, which, while not classified as critical or high severity, warrants attention. The presence of file operations and a substantial number of external HTTP requests also represent potential attack vectors, even if currently secured by other mechanisms. The lack of shortcodes, REST API routes, and cron events, while reducing the attack surface, also means these potential entry points are not being leveraged for functionality that might otherwise require robust security.

Overall, the plugin appears to be developed with security in mind, with strong foundational practices in place. The primary concern lies in the single unsanitized path identified by the taint analysis, which could potentially lead to vulnerabilities if not addressed. The plugin's history of zero vulnerabilities is a significant strength, but it's important to remain vigilant, especially given the identified taint flow.

Key Concerns

  • Flow with unsanitized path found
  • File operation present
  • External HTTP requests present
  • Output escaping not fully implemented
Vulnerabilities
None known

AVIR Social Auto Poster Ultimate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AVIR Social Auto Poster Ultimate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
56
136 escaped
Nonce Checks
11
Capability Checks
12
File Operations
1
External Requests
12
Bundled Libraries
0

Output Escaping

71% escaped192 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<class-meta-box> (includes\admin\class-meta-box.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AVIR Social Auto Poster Ultimate Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 7

authwp_ajax_avir_fbp_test_connectionincludes\admin\class-admin-settings.php:15
authwp_ajax_avir_fbp_toggle_statusincludes\admin\class-meta-box.php:27
authwp_ajax_avir_fbp_regenerate_excerptincludes\admin\class-meta-box.php:29
authwp_ajax_avir_fbp_post_to_socialincludes\admin\class-meta-box.php:30
authwp_ajax_avir_fbp_toggle_facebook_statusincludes\admin\class-meta-box.php:33
authwp_ajax_avir_fbp_toggle_instagram_statusincludes\admin\class-meta-box.php:34
authwp_ajax_avir_fbp_dismiss_reviewincludes\class-review-reminder.php:20
WordPress Hooks 23
filteravir_fbp_post_typesavir-social-auto-poster-ultimate.php:46
actioninitavir-social-auto-poster-ultimate.php:56
actionadmin_initavir-social-auto-poster-ultimate.php:69
actionadmin_menuavir-social-auto-poster-ultimate.php:79
actionadmin_menuincludes\admin\class-admin-settings.php:12
actionadmin_initincludes\admin\class-admin-settings.php:13
actionadmin_enqueue_scriptsincludes\admin\class-admin-settings.php:14
actionadd_meta_boxesincludes\admin\class-meta-box.php:10
actionadmin_noticesincludes\admin\class-meta-box.php:12
actionadmin_enqueue_scriptsincludes\admin\class-meta-box.php:13
filtermanage_posts_columnsincludes\admin\class-meta-box.php:16
actionmanage_posts_custom_columnincludes\admin\class-meta-box.php:17
filtermanage_edit-post_sortable_columnsincludes\admin\class-meta-box.php:18
filtermanage_pages_columnsincludes\admin\class-meta-box.php:21
actionmanage_pages_custom_columnincludes\admin\class-meta-box.php:22
filtermanage_edit-page_sortable_columnsincludes\admin\class-meta-box.php:23
actionpre_get_postsincludes\admin\class-meta-box.php:25
actionpre_get_postsincludes\admin\class-meta-box.php:26
filterposts_orderbyincludes\admin\class-meta-box.php:1581
filterposts_orderbyincludes\admin\class-meta-box.php:1645
actionadmin_initincludes\class-review-reminder.php:19
actionadmin_enqueue_scriptsincludes\class-review-reminder.php:22
actionadmin_noticesincludes\class-review-reminder.php:105
Maintenance & Trust

AVIR Social Auto Poster Ultimate Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 24, 2025
PHP min version7.0
Downloads596

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

AVIR Social Auto Poster Ultimate Developer Profile

Avir Media

2 plugins · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AVIR Social Auto Poster Ultimate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/avir-social-auto-poster-ultimate/public/css/admin.css/wp-content/plugins/avir-social-auto-poster-ultimate/public/js/admin.js
Script Paths
/wp-content/plugins/avir-social-auto-poster-ultimate/public/js/admin.js
Version Parameters
avir-social-auto-poster-ultimate/public/css/admin.css?ver=avir-social-auto-poster-ultimate/public/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
raw-datatoggle-raw-data
Data Attributes
data-nonce="avir-fbp-admin-nonce"
JS Globals
avirFbpData
REST Endpoints
/wp-json/avir_fbp/v1
FAQ

Frequently Asked Questions about AVIR Social Auto Poster Ultimate