
FoxyBookmark Security & Risk Analysis
wordpress.org/plugins/foxy-bookmarkFor content by the visitor in social networks
Is FoxyBookmark Safe to Use in 2026?
Generally Safe
Score 85/100FoxyBookmark has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "foxy-bookmark" v1.0.0 plugin presents a mixed security profile. On the positive side, it exhibits a remarkably small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all identified SQL queries utilize prepared statements, and there are no recorded CVEs, indicating a potentially clean history. This suggests a degree of diligence in avoiding common vulnerability vectors.
However, significant concerns arise from the static analysis. The complete lack of output escaping for all identified outputs is a critical weakness, potentially exposing the application to cross-site scripting (XSS) attacks. The absence of nonce and capability checks on any entry points, coupled with file operations and external HTTP requests, creates opportunities for unauthorized actions or data leakage if these operations are not inherently secure or properly validated. The lack of taint analysis results might be due to the limited attack surface, but it doesn't negate the risks associated with unescaped output and missing authorization checks.
In conclusion, while the plugin's limited attack surface and use of prepared statements are commendable, the pervasive lack of output escaping and authorization checks are significant security liabilities. The absence of past vulnerabilities could be attributed to its low exposure or simply luck, rather than inherent security. The identified code signals point towards a need for substantial hardening, particularly around input sanitization and output encoding.
Key Concerns
- All identified outputs are unescaped
- No nonce checks
- No capability checks
- Performs file operations
- Performs external HTTP requests
FoxyBookmark Security Vulnerabilities
FoxyBookmark Code Analysis
Output Escaping
FoxyBookmark Attack Surface
WordPress Hooks 4
Maintenance & Trust
FoxyBookmark Maintenance & Trust
Maintenance Signals
Community Trust
FoxyBookmark Alternatives
Hubbub Lite – Fast, free social sharing and follow buttons
social-pug
Your content is worth sharing. Let's makes it easier!
Social Share, Social Login and Social Comments Plugin – Super Socializer
super-socializer
The unique Social Plugin to let you integrate Social Login, Social Share, Social Comments and Social Media follow at your website
Nobs • Share Buttons
juiz-social-post-sharer
Juiz Social Post Sharer is now Nobs • Share Buttons. Add beautiful share buttons in your posts to allow visitors to share your content on social media …
Highlight and Share – Unobtrusive and Lightweight Content Sharing
highlight-and-share
A lightweight social sharing plugin for showing social networks when users highlight text, share images, headlines, or use Click to Share.
Simple Auto-Poster for Bluesky
simple-auto-poster-for-bluesky
Simple Auto Poster for Bluesky is a set and forget plugin that automatically shares on bluesky whenever a post is published from WordPress.
FoxyBookmark Developer Profile
1 plugin · 10 total installs
How We Detect FoxyBookmark
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/foxy-bookmark/foxy-bookmarks.css/wp-content/plugins/foxy-bookmark/foxy-bookmarks.jsHTML / DOM Fingerprints
foxywrapitin1in2foxy-bookmarks<!-- the height of the icons (29px) --><!-- Now the plugin supports insertion on your site's main page for those of you who use themes that post the entire content of posts on the homepage. -->id="foxy-bookmarks"name="foxy-bookmarks"id="position-above"id="position-below"id="position-manual"id="reloption"+9 morevar plugoptsvar vNumvar OPTIONSvar PLUGINNAMEvar PLUGPATH