BS Social Icons Security & Risk Analysis
wordpress.org/plugins/bs-social-iconsPowerful easy, quick and simple social icons integration.
Is BS Social Icons Safe to Use in 2026?
Generally Safe
Score 85/100BS Social Icons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bs-social-icons" v0.0.1 plugin exhibits a generally good security posture based on the provided static analysis. The plugin demonstrates strong adherence to several security best practices, including the complete absence of dangerous functions, file operations, and external HTTP requests. Furthermore, all SQL queries utilize prepared statements, and the plugin includes nonce and capability checks, indicating an effort to protect its entry points. The vulnerability history also shows no recorded CVEs, suggesting a clean track record.
However, a significant concern lies in the output escaping. Only 15% of the observed output points are properly escaped, meaning that 85% of outputs are potentially vulnerable to Cross-Site Scripting (XSS) attacks. Given that the plugin has 2 entry points (1 AJAX handler and 1 shortcode) and no explicit mention of input sanitization for these handlers and shortcodes, this low rate of output escaping presents a notable risk. While there are no identified critical or high severity taint flows, and the attack surface appears to have authorization checks, the unescaped outputs could still lead to medium or low severity XSS vulnerabilities if an attacker can inject malicious scripts through user-controllable data that is then displayed by the plugin.
In conclusion, "bs-social-icons" v0.0.1 has strengths in its secure handling of database operations, absence of dangerous code patterns, and the presence of some authorization checks. Nevertheless, the critically low rate of output escaping poses a significant security weakness that requires immediate attention to prevent potential XSS vulnerabilities.
Key Concerns
- Low output escaping rate (15%)
BS Social Icons Security Vulnerabilities
BS Social Icons Code Analysis
Output Escaping
Data Flow Analysis
BS Social Icons Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
BS Social Icons Maintenance & Trust
Maintenance Signals
Community Trust
BS Social Icons Alternatives
Simple Custom CSS and JS
custom-css-js
Easily add Custom CSS or JS to your website with an awesome editor.
Simple Custom CSS Plugin
simple-custom-css
Add Custom CSS to your WordPress site without any hassles.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
WP Add Custom CSS
wp-add-custom-css
Add custom css to the whole website and to specific posts and pages.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
BS Social Icons Developer Profile
1 plugin · 0 total installs
How We Detect BS Social Icons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bs-social-icons/css/bsoft_social.css/wp-content/plugins/bs-social-icons/js/customescript.js/wp-content/plugins/bs-social-icons/js/customescript.jsbsoft-icon-css?ver=bsoft-social-script?ver=HTML / DOM Fingerprints
bsoft-esi-shadowbsoft-sec-titledata-bs-social-icon-nonce[Bsoft_Social_Icon]