BestWebSoft's LinkedIn Security & Risk Analysis

wordpress.org/plugins/bws-linkedin

Add LinkedIn Share and Follow buttons to WordPress posts, pages and widgets.

200 active installs v1.1.5 PHP + WP 5.6+ Updated Jun 9, 2025
likedinlinedinlinkedinlinkedin-pluginlinkedln
100
A · Safe
CVEs total1
Unpatched0
Last CVEApr 17, 2017
Safety Verdict

Is BestWebSoft's LinkedIn Safe to Use in 2026?

Generally Safe

Score 100/100

BestWebSoft's LinkedIn has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 17, 2017Updated 9mo ago
Risk Assessment

The BWS LinkedIn plugin, in version 1.1.5, demonstrates a generally good security posture with robust output escaping and a significant number of nonce and capability checks. The static analysis reveals no critical or high severity taint flows, and all identified SQL queries utilize prepared statements, which is a positive indicator. However, the plugin's history includes a medium severity Cross-Site Scripting (XSS) vulnerability reported in 2017, which, although now patched, suggests a past susceptibility to input sanitization issues. The presence of external HTTP requests without explicit mention of their security context could represent a minor concern if not handled carefully, and the limited number of authorization checks on entry points, while currently zero, warrants vigilance as the plugin evolves. Overall, while the current code exhibits many secure coding practices, the past vulnerability underscores the importance of ongoing security reviews and prompt patching of any future issues.

Key Concerns

  • Past medium severity XSS vulnerability
  • 6 external HTTP requests, potential for insecure communication
Vulnerabilities
1

BestWebSoft's LinkedIn Security Vulnerabilities

CVEs by Year

1 CVE in 2017
2017
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2017-18516medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BestWebSoft's LinkedIn < 1.0.5 - Cross-Site Scripting

Apr 17, 2017 Patched in 1.0.5 (2678d)
Code Analysis
Analyzed Mar 16, 2026

BestWebSoft's LinkedIn Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
2 prepared
Unescaped Output
17
469 escaped
Nonce Checks
20
Capability Checks
3
File Operations
2
External Requests
6
Bundled Libraries
0

SQL Query Safety

50% prepared4 total queries

Output Escaping

97% escaped486 total outputs
Data Flows
All sanitized

Data Flow Analysis

6 flows
bws_add_menu_render (bws_menu\bws_menu.php:18)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BestWebSoft's LinkedIn Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_bws_submit_request_feature_actionbws_menu\class-bws-settings.php:1466
authwp_ajax_bws_submit_uninstall_reason_actionbws_menu\deactivation-form.php:433

Shortcodes 1

[bws_linkedin] bws-linkedin.php:639
WordPress Hooks 23
actionadmin_menubws-linkedin.php:628
actioninitbws-linkedin.php:630
actionadmin_initbws-linkedin.php:631
actionplugins_loadedbws-linkedin.php:632
actionadmin_enqueue_scriptsbws-linkedin.php:634
actionwp_enqueue_scriptsbws-linkedin.php:635
filterscript_loader_tagbws-linkedin.php:636
filterpgntn_callbackbws-linkedin.php:637
filterthe_contentbws-linkedin.php:640
filterbws_shortcode_button_contentbws-linkedin.php:642
filterbody_classbws-linkedin.php:644
filterplugin_action_linksbws-linkedin.php:646
filterplugin_row_metabws-linkedin.php:647
actionadmin_noticesbws-linkedin.php:649
filterload_textdomain_mofilebws_menu\bws_functions.php:43
filtermce_external_pluginsbws_menu\bws_functions.php:1146
filtermce_buttonsbws_menu\bws_functions.php:1147
actionadmin_initbws_menu\bws_functions.php:1433
actionadmin_enqueue_scriptsbws_menu\bws_functions.php:1434
actionadmin_headbws_menu\bws_functions.php:1435
actionadmin_footerbws_menu\bws_functions.php:1436
actionadmin_noticesbws_menu\bws_functions.php:1438
actionwp_enqueue_scriptsbws_menu\bws_functions.php:1440
Maintenance & Trust

BestWebSoft's LinkedIn Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 9, 2025
PHP min version
Downloads14K

Community Trust

Rating84/100
Number of ratings5
Active installs200
Developer Profile

BestWebSoft's LinkedIn Developer Profile

bestweblayout

32 plugins · 17K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
1944 days
View full developer profile
Detection Fingerprints

How We Detect BestWebSoft's LinkedIn

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bws-linkedin/css/bws-linkedin-frontend.css/wp-content/plugins/bws-linkedin/js/bws-linkedin-frontend.js
Script Paths
/wp-content/plugins/bws-linkedin/js/bws-linkedin-frontend.js
Version Parameters
bws-linkedin/css/bws-linkedin-frontend.css?ver=bws-linkedin/js/bws-linkedin-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
bws-linkedin-share-blockbws-linkedin-follow-block
HTML Comments
<!-- BestWebSoft's LinkedIn --><!-- pls -->
JS Globals
bws_linkedin_options
Shortcode Output
[linkedin]
FAQ

Frequently Asked Questions about BestWebSoft's LinkedIn