DamnSexyBookmarks Security & Risk Analysis

wordpress.org/plugins/damnsexybookmarks

Adds a social bookmarking menu to your posts/pages/index. Based on Josh Jones' SexyBookmarks plugin: http://eight7teen.com/sexy-bookmarks

10 active installs v1.0.1 PHP + WP 2.7+ Updated Apr 24, 2009
bookmarks-menudeliciousdiggfurlsocial-bookmarking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DamnSexyBookmarks Safe to Use in 2026?

Generally Safe

Score 85/100

DamnSexyBookmarks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The static analysis of damnsexybookmarks v1.0.1 reveals a plugin with a seemingly minimal attack surface, reporting zero AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. Furthermore, there are no recorded vulnerabilities in its history, suggesting a relatively stable and secure past. The code also demonstrates good practices by utilizing prepared statements for all SQL queries. However, a significant concern arises from the complete lack of output escaping. This means that any dynamic content generated by the plugin could be vulnerable to cross-site scripting (XSS) attacks, as user-provided data is not being sanitized before being displayed to the user. The presence of file operations and external HTTP requests without explicit mention of sanitization or permission checks also warrants caution, as these could potentially be exploited if not handled securely.

Key Concerns

  • 0% output escaping
  • 0 capability checks
  • 0 nonce checks
Vulnerabilities
None known

DamnSexyBookmarks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

DamnSexyBookmarks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Attack Surface

DamnSexyBookmarks Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_headdamn-sexy-bookmarks.php:412
actionadmin_headdamn-sexy-bookmarks.php:422
actionadmin_menudamn-sexy-bookmarks.php:434
filterthe_contentdamn-sexy-bookmarks.php:435
Maintenance & Trust

DamnSexyBookmarks Maintenance & Trust

Maintenance Signals

WordPress version tested2.7.1
Last updatedApr 24, 2009
PHP min version
Downloads13K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

DamnSexyBookmarks Developer Profile

normanyung

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DamnSexyBookmarks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/damn-sexy-bookmarks/damn-sexy-bookmarks.css/wp-content/plugins/damn-sexy-bookmarks/damn-sexy-bookmarks.js
Script Paths
/wp-content/plugins/damn-sexy-bookmarks/damn-sexy-bookmarks.js
Version Parameters
damn-sexy-bookmarks/damn-sexy-bookmarks.css?ver=damn-sexy-bookmarks/damn-sexy-bookmarks.js?ver=

HTML / DOM Fingerprints

CSS Classes
sexywrapitin1in2
Data Attributes
data-titledata-icon
JS Globals
damnSexyBookmarks
Shortcode Output
[damn-sexy-bookmarks][damn_sexy_bookmarks]
FAQ

Frequently Asked Questions about DamnSexyBookmarks