Clikran – Social Icons Security & Risk Analysis

wordpress.org/plugins/clikran-social-icons

Easily add Follow us social icons anywhere on your site using a shortcode or widget. Fully customizable from a simple, user-friendly settings page.

0 active installs v1.0.2 PHP 7.2+ WP 5.0+ Updated Aug 14, 2025
follow-buttonssocial-cardssocial-icons-widgetsocial-media-icons
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Clikran – Social Icons Safe to Use in 2026?

Generally Safe

Score 100/100

Clikran – Social Icons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The clikran-social-icons plugin version 1.0.2 exhibits a generally good security posture based on the provided static analysis. The plugin correctly uses prepared statements for all SQL queries, properly escapes all output, and has no external HTTP requests, which are all positive indicators of secure coding practices. The absence of critical or high-severity taint flows further suggests a low risk of common injection vulnerabilities. The plugin also has a clean vulnerability history with no known CVEs, implying a history of stable and secure development.

However, there are areas of concern. The most significant is the complete lack of nonce checks and capability checks. This means that any functionality exposed, even if it's just through a shortcode, could potentially be executed by any user, regardless of their role or permissions. While the current attack surface appears small (only one shortcode with no apparent associated unprotected AJAX or REST API endpoints), this lack of authorization checks presents a potential weakness. If future versions introduce new functionalities that are sensitive, they would be vulnerable without these essential security measures.

In conclusion, the plugin demonstrates strong practices regarding SQL and output handling, and a clean historical record. The absence of vulnerabilities in the past is encouraging. Nevertheless, the critical absence of nonce and capability checks on its entry points represents a significant security oversight that could lead to unauthorized actions if the shortcode's functionality is ever exploited or expanded upon in a sensitive manner. This warrants attention to ensure future robustness.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Clikran – Social Icons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Clikran – Social Icons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
79 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped79 total outputs
Attack Surface

Clikran – Social Icons Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[clikran] includes\shortcode.php:131
WordPress Hooks 7
actionwp_enqueue_scriptsclikran.php:34
actionadmin_enqueue_scriptsclikran.php:63
actionadmin_menuincludes\admin.php:16
actionadmin_initincludes\admin.php:27
actionadmin_enqueue_scriptsincludes\admin.php:198
actionadmin_enqueue_scriptsincludes\settings-page.php:7
actionwp_enqueue_scriptsincludes\settings-page.php:15
Maintenance & Trust

Clikran – Social Icons Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 14, 2025
PHP min version7.2
Downloads296

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Clikran – Social Icons Developer Profile

Kiran Samileti

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Clikran – Social Icons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/clikran-social-icons/assets/css/all.min.css/wp-content/plugins/clikran-social-icons/assets/css/style.css/wp-content/plugins/clikran-social-icons/assets/css/admin.css/wp-content/plugins/clikran-social-icons/assets/js/admin.js
Script Paths
/wp-content/plugins/clikran-social-icons/assets/js/admin.js
Version Parameters
clikran-social-icons/assets/css/all.min.css?ver=clikran-social-icons/assets/css/style.css?ver=clikran-social-icons/assets/css/admin.css?ver=clikran-social-icons/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
clikran-social-icons-listclikran-social-icon-itemclikran-social-icon-linkclikran-social-icon-wrapperclikran-social-icon-text
Data Attributes
data-clikran-card-id
Shortcode Output
<div class="clikran-social-icons-container">
FAQ

Frequently Asked Questions about Clikran – Social Icons