Clikran – Social Icons Security & Risk Analysis
wordpress.org/plugins/clikran-social-iconsEasily add Follow us social icons anywhere on your site using a shortcode or widget. Fully customizable from a simple, user-friendly settings page.
Is Clikran – Social Icons Safe to Use in 2026?
Generally Safe
Score 100/100Clikran – Social Icons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The clikran-social-icons plugin version 1.0.2 exhibits a generally good security posture based on the provided static analysis. The plugin correctly uses prepared statements for all SQL queries, properly escapes all output, and has no external HTTP requests, which are all positive indicators of secure coding practices. The absence of critical or high-severity taint flows further suggests a low risk of common injection vulnerabilities. The plugin also has a clean vulnerability history with no known CVEs, implying a history of stable and secure development.
However, there are areas of concern. The most significant is the complete lack of nonce checks and capability checks. This means that any functionality exposed, even if it's just through a shortcode, could potentially be executed by any user, regardless of their role or permissions. While the current attack surface appears small (only one shortcode with no apparent associated unprotected AJAX or REST API endpoints), this lack of authorization checks presents a potential weakness. If future versions introduce new functionalities that are sensitive, they would be vulnerable without these essential security measures.
In conclusion, the plugin demonstrates strong practices regarding SQL and output handling, and a clean historical record. The absence of vulnerabilities in the past is encouraging. Nevertheless, the critical absence of nonce and capability checks on its entry points represents a significant security oversight that could lead to unauthorized actions if the shortcode's functionality is ever exploited or expanded upon in a sensitive manner. This warrants attention to ensure future robustness.
Key Concerns
- Missing nonce checks
- Missing capability checks
Clikran – Social Icons Security Vulnerabilities
Clikran – Social Icons Code Analysis
Output Escaping
Clikran – Social Icons Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Clikran – Social Icons Maintenance & Trust
Maintenance Signals
Community Trust
Clikran – Social Icons Alternatives
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Popular Brand Icons – Simple Icons
simple-icons
An easy to use lightweight SVG icons plugin with over 1500+ brand icons. Use these icons in your menus, widgets, posts, or pages.
ShareThis Follow Buttons
sharethis-follow-buttons
Integrate ShareThis Follow Buttons seamlessly into your WordPress site.
SimpleSocial
simplesocial
Display icons for your social media profile links.
Simple Follow Buttons
simple-follow-buttons
A simple plugin that enables you to add follow buttons to all of your posts and/or pages.
Clikran – Social Icons Developer Profile
1 plugin · 0 total installs
How We Detect Clikran – Social Icons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clikran-social-icons/assets/css/all.min.css/wp-content/plugins/clikran-social-icons/assets/css/style.css/wp-content/plugins/clikran-social-icons/assets/css/admin.css/wp-content/plugins/clikran-social-icons/assets/js/admin.js/wp-content/plugins/clikran-social-icons/assets/js/admin.jsclikran-social-icons/assets/css/all.min.css?ver=clikran-social-icons/assets/css/style.css?ver=clikran-social-icons/assets/css/admin.css?ver=clikran-social-icons/assets/js/admin.js?ver=HTML / DOM Fingerprints
clikran-social-icons-listclikran-social-icon-itemclikran-social-icon-linkclikran-social-icon-wrapperclikran-social-icon-textdata-clikran-card-id<div class="clikran-social-icons-container">