Social Pin & Media Showcase Security & Risk Analysis

wordpress.org/plugins/dynamic-pin-it-button-on-image-hover

Adds a Pinterest “Save” button on images in posts, categories, and archives, plus TikTok, Instagram, and YouTube Elementor widgets.

10 active installs v1.1.5 PHP + WP 5.5+ Updated Unknown
pin-imagespin-it-buttonpin-photopinterest
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Social Pin & Media Showcase Safe to Use in 2026?

Generally Safe

Score 100/100

Social Pin & Media Showcase has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "dynamic-pin-it-button-on-image-hover" v1.1.5 demonstrates a generally strong security posture based on the provided static analysis. The absence of known vulnerabilities in its history and the complete lack of critical or high-severity taint analysis flows are significant positive indicators. All SQL queries are properly prepared, and there are no file operations, reducing common attack vectors.

However, there are areas that warrant attention. The analysis reveals that only 72% of output is properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities in the remaining 28%. Furthermore, the complete absence of nonce checks across all entry points (AJAX, REST API, shortcodes, cron events) is a notable concern, as it bypasses a fundamental WordPress security mechanism for verifying user intent. While there's a single capability check, its scope and effectiveness are not detailed, and the overall attack surface is stated as zero, which is unusual and might suggest an incomplete analysis or a very simple plugin.

In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL practices, the potential for unescaped output and the complete lack of nonce checks present tangible risks that should be addressed to improve its overall security. The absence of identified entry points needs further investigation as it's an anomaly.

Key Concerns

  • Output escaping not fully implemented
  • Missing nonce checks on entry points
Vulnerabilities
None known

Social Pin & Media Showcase Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Social Pin & Media Showcase Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
10
26 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

72% escaped36 total outputs
Attack Surface

Social Pin & Media Showcase Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actioninitdynamic-pin-it-button-on-image-hover.php:91
actionplugins_loadeddynamic-pin-it-button-on-image-hover.php:92
actionplugins_loadeddynamic-pin-it-button-on-image-hover.php:93
actionadmin_menuincludes\Admin\Dynamic_Pin_It_Settings.php:21
actionadmin_initincludes\Admin\Dynamic_Pin_It_Settings.php:22
actionelementor/widgets/registerincludes\Elementor\class-elementor-loader.php:12
actionelementor/frontend/after_enqueue_stylesincludes\Elementor\class-elementor-loader.php:13
actionelementor/frontend/after_enqueue_scriptsincludes\Elementor\class-elementor-loader.php:14
actionwp_enqueue_scriptsincludes\Enqueue.php:18
filterscript_loader_tagincludes\Enqueue.php:19
actionwp_footerincludes\Frontend\Dynamic_Pin_It_Frontend.php:19
Maintenance & Trust

Social Pin & Media Showcase Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Social Pin & Media Showcase Developer Profile

Maidul

10 plugins · 1K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
126 days
View full developer profile
Detection Fingerprints

How We Detect Social Pin & Media Showcase

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dynamic-pin-it-button-on-image-hover/assets/css/style.css/wp-content/plugins/dynamic-pin-it-button-on-image-hover/assets/js/script.js
Script Paths
/wp-content/plugins/dynamic-pin-it-button-on-image-hover/assets/js/script.js
Version Parameters
dynamic-pin-it-button-on-image-hover/assets/css/style.css?ver=dynamic-pin-it-button-on-image-hover/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
dwl-pin-it-button
Data Attributes
data-dynamic-pin-it-id
JS Globals
dwlPinItButton
FAQ

Frequently Asked Questions about Social Pin & Media Showcase