
Easy Google+ Widget Security & Risk Analysis
wordpress.org/plugins/easy-googles-widgetGoogles+ widget which provides you public post from your timeline.
Is Easy Google+ Widget Safe to Use in 2026?
Generally Safe
Score 85/100Easy Google+ Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "easy-googles-widget" plugin version 0.2.7.2 exhibits a concerning security posture due to significant weaknesses in its handling of user input and authorization. The static analysis reveals a small but critical attack surface consisting of two AJAX handlers, neither of which has any authentication checks. This means any unauthenticated user can potentially trigger these handlers. Furthermore, all identified output (48 instances) is unescaped, creating a high risk of cross-site scripting (XSS) vulnerabilities. The taint analysis shows three flows with unsanitized paths, indicating potential for malicious data to be processed without proper validation, although no critical or high severity taint flows were specifically identified. The plugin's history of zero known CVEs is a positive sign, suggesting a lack of publicly disclosed vulnerabilities, but this is overshadowed by the immediate and severe risks present in the current codebase. The use of the `create_function` dangerous function is also a red flag. While the plugin uses prepared statements for SQL queries, this is a minor positive against the backdrop of critical security flaws. The lack of nonces and capability checks on its entry points, combined with the unescaped output, makes this plugin a significant risk for exploitation, particularly through XSS attacks.
Key Concerns
- AJAX handlers without auth checks
- All outputs are unescaped
- Taint flows with unsanitized paths
- Dangerous function create_function used
- No nonce checks
- No capability checks
Easy Google+ Widget Security Vulnerabilities
Easy Google+ Widget Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Easy Google+ Widget Attack Surface
AJAX Handlers 2
WordPress Hooks 1
Maintenance & Trust
Easy Google+ Widget Maintenance & Trust
Maintenance Signals
Community Trust
Easy Google+ Widget Alternatives
All-Social FW Style
all-social-fw-style-widget
Todos tus sitios web en un solo widget: Facebook, Twitter, Google Plus y FeedBurner.
RS Social Sidebar
rs-social-sidebar
Another social plugin :). Difference is the hover effect.
Metro Style Social Widget
metro-style-social-widget
Metro Style Social Network Widget
Jamie Social Icons
jamie-social-icons
Share your posts & pages with your favourite social sites - Twitter, Facebook, Google Plus, Pinterest And LinkedIn and now trackable with your Goo …
Rel Publisher
rel-publisher
Rel Publisher is a simple plugin that lets you easily add <link rel="publisher" /> to your site.
Easy Google+ Widget Developer Profile
3 plugins · 30 total installs
How We Detect Easy Google+ Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-googles-widget/ozoGPWidgetStyle.php/wp-content/plugins/easy-googles-widget/ozoGPWidgetScript.jseasy-googles-widget/ozoGPWidgetStyle.php?ver=easy-googles-widget/ozoGPWidgetScript.js?ver=HTML / DOM Fingerprints
ozoGPAuthorozoGPstatusphotophotoshrozoGPcommentsdata-widget-idajax_object