
Branded Social Images – Open Graph Images with logo and extra text layer Security & Risk Analysis
wordpress.org/plugins/branded-social-imagesThe simplest way to brand your social images. Provide all your social images (Open Graph images) with your brand en text. In just a few clicks.
Is Branded Social Images – Open Graph Images with logo and extra text layer Safe to Use in 2026?
Generally Safe
Score 100/100Branded Social Images – Open Graph Images with logo and extra text layer has a strong security track record. Known vulnerabilities have been patched promptly.
The branded-social-images plugin v1.1.4 presents a mixed security profile. On the positive side, the static analysis shows a remarkably clean codebase in several areas. There are no observed AJAX handlers, REST API routes, shortcodes, or cron events, indicating a very limited attack surface. Furthermore, all SQL queries are properly prepared, and all output is correctly escaped, which are strong indicators of good security practices. The absence of taint analysis findings with unsanitized paths is also a positive sign.
However, significant concerns arise from the presence of a dangerous function (`exec`) and a lack of capability checks and nonce checks. The `exec` function, if used improperly with user-supplied input, can lead to arbitrary code execution. The absence of capability checks on any potential entry points means that even if there were any, they might be accessible to users without the necessary permissions. The previous vulnerability history, particularly the medium severity issue related to missing authorization, further highlights a pattern of potential authorization bypasses or privilege escalation vulnerabilities within the plugin.
While the current version shows no unpatched CVEs and a limited attack surface, the presence of `exec` without evident authorization controls is a critical risk. The history of authorization issues suggests that the developers may struggle with correctly implementing permission checks. The strengths in SQL and output escaping are overshadowed by the potential for command injection and the recurring authorization weaknesses. Therefore, users should exercise caution and consider the implications of using a plugin with these identified risks.
Key Concerns
- Presence of dangerous function 'exec'
- Missing capability checks
- Missing nonce checks
- Previous medium severity vulnerability
Branded Social Images – Open Graph Images with logo and extra text layer Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Branded Social Images <= 1.1.0 - Missing Authorization leading to Unauthenticated Plugin Settings Updates
Branded Social Images – Open Graph Images with logo and extra text layer Code Analysis
Dangerous Functions Found
Branded Social Images – Open Graph Images with logo and extra text layer Attack Surface
WordPress Hooks 2
Maintenance & Trust
Branded Social Images – Open Graph Images with logo and extra text layer Maintenance & Trust
Maintenance Signals
Community Trust
Branded Social Images – Open Graph Images with logo and extra text layer Alternatives
WP Social Preview
wp-social-preview
Increase social media engagement by previewing and managing how your content will look on social media sites before sharing it!
Sharing Image
sharing-image
Sharing Image is a WordPress plugin for generating sharing posters in social networks.
MightyShare – Auto-Generated Social Media Images
mightyshare
Automatically generate social share preview images with MightyShare!
Dynamic Open Graph Images – OpenGraph.xyz
opengraph-xyz
Enhance your WordPress site with dynamic Open Graph images.
OGPanic
ogpanic
OGPanic generates beautiful og-images automatically from your post's title, featured image and etc.
Branded Social Images – Open Graph Images with logo and extra text layer Developer Profile
4 plugins · 12K total installs
How We Detect Branded Social Images – Open Graph Images with logo and extra text layer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/branded-social-images/assets/css/admin.css/wp-content/plugins/branded-social-images/assets/css/frontend.css/wp-content/plugins/branded-social-images/assets/js/admin.js/wp-content/plugins/branded-social-images/assets/js/frontend.jsbranded-social-images/assets/css/admin.css?ver=branded-social-images/assets/css/frontend.css?ver=branded-social-images/assets/js/admin.js?ver=branded-social-images/assets/js/frontend.js?ver=HTML / DOM Fingerprints
bsi-admin-wrapperbsi-frontend-wrapperNote from the developers.We know the plugin code is not perfect.There is a lot of room for improvement, but in ourenthusiasm to share this with you, we could not wait for everything to be polished.+13 moredata-bsi-idwindow.bsi_admin_params