WP2Social Auto Publish Security & Risk Analysis

wordpress.org/plugins/facebook-auto-publish

Publish posts automatically to Facebook page.

10K active installs v2.4.11 PHP + WP 3.0+ Updated Feb 18, 2026
facebookfacebook-auto-publishwp2fb-auto-publishwp2socialwp2social-auto-publish
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 7, 2025
Safety Verdict

Is WP2Social Auto Publish Safe to Use in 2026?

Generally Safe

Score 99/100

WP2Social Auto Publish has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 7, 2025Updated 1mo ago
Risk Assessment

The "facebook-auto-publish" plugin v2.4.11 exhibits a mixed security posture. On the positive side, it has a contained attack surface with all identified entry points (AJAX handlers) protected by authentication checks. The plugin also demonstrates good practices by utilizing prepared statements for a majority of its SQL queries and implementing a significant number of nonce and capability checks. However, the presence of the `unserialize` function is a notable concern, as it can be a vector for object injection vulnerabilities if not handled with extreme care and strict input validation. The taint analysis, while not revealing critical or high severity issues, did identify two flows with unsanitized paths, which warrants further investigation to ensure no exploitable conditions exist. The plugin's vulnerability history shows one medium severity CVE related to Cross-Site Scripting (XSS) that was last patched in late 2025. While this CVE is not currently unpatched, it indicates a past susceptibility to XSS, which could re-emerge if similar coding patterns are present and not thoroughly reviewed. Overall, the plugin has strengths in authentication and SQL handling but requires vigilance regarding the use of dangerous functions and potential for XSS or injection vulnerabilities stemming from unsanitized data.

Key Concerns

  • Use of unserialize function
  • Flows with unsanitized paths detected
  • One medium severity CVE historically
  • Low percentage of properly escaped output
Vulnerabilities
1

WP2Social Auto Publish Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-12064medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP2Social Auto Publish <= 2.4.7 - Reflected Cross-Site Scripting via PostMessage

Nov 7, 2025 Patched in 2.4.8 (1d)
Code Analysis
Analyzed Mar 16, 2026

WP2Social Auto Publish Code Analysis

Dangerous Functions
1
Raw SQL Queries
3
6 prepared
Unescaped Output
289
64 escaped
Nonce Checks
13
Capability Checks
7
File Operations
0
External Requests
8
Bundled Libraries
0

Dangerous Functions Found

unserialize$arrval=unserialize($status);admin\logs.php:84

SQL Query Safety

67% prepared9 total queries

Output Escaping

18% escaped353 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

10 flows2 with unsanitized paths
xyz_fbap_addpostmetatags (admin\metabox.php:63)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP2Social Auto Publish Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_xyz_fbap_ajax_backlinkadmin\ajax-actions.php:3
authwp_ajax_xyz_fbap_selected_pages_auto_updateadmin\ajax-actions.php:29
authwp_ajax_xyz_fbap_xyzscripts_accinfo_auto_updateadmin\ajax-actions.php:56
authwp_ajax_xyz_fbap_del_entriesadmin\ajax-actions.php:75
authwp_ajax_xyz_fbap_del_fb_entriesadmin\ajax-actions.php:115
WordPress Hooks 13
actionadmin_noticesadmin\admin-notices.php:72
actionadmin_noticesadmin\admin-notices.php:152
actionadmin_initadmin\admin-notices.php:154
actionadmin_menuadmin\menu.php:3
actionadmin_enqueue_scriptsadmin\menu.php:30
actionwp_headadmin\menu.php:91
actionadd_meta_boxesadmin\metabox.php:3
actionsave_postadmin\publish.php:3
actiontransition_post_statusadmin\publish.php:19
actioninitfacebook-auto-publish.php:37
actionwp_footerfacebook-auto-publish.php:68
actionadmin_initfacebook-auto-publish.php:84
filterplugin_row_metaxyz-functions.php:160
Maintenance & Trust

WP2Social Auto Publish Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 18, 2026
PHP min version
Downloads1.1M

Community Trust

Rating96/100
Number of ratings641
Active installs10K
Developer Profile

WP2Social Auto Publish Developer Profile

f1logic

15 plugins · 142K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
352 days
View full developer profile
Detection Fingerprints

How We Detect WP2Social Auto Publish

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP2Social Auto Publish