GNA Korean SNS Security & Risk Analysis

wordpress.org/plugins/gna-korean-sns

Sharing your post via Korean SNS such as Kakao Talk, Naver Line, Naver Blog, Facebook, Twitter and so on.

10 active installs v0.9.7 PHP + WP 3.9+ Updated Sep 5, 2016
gnakakao-talksns-sharing
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GNA Korean SNS Safe to Use in 2026?

Generally Safe

Score 85/100

GNA Korean SNS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "gna-korean-sns" plugin v0.9.7 exhibits a generally good security posture, particularly in its handling of SQL queries and the absence of known vulnerabilities. The code signals indicate a conscious effort to use prepared statements for all SQL operations, which is a significant strength. The presence of a nonce check, even with no explicit AJAX handlers, suggests some awareness of security best practices. Furthermore, the plugin has no recorded vulnerabilities, historical or current, and no common vulnerability types have been associated with it. This pattern of no reported issues is a positive indicator.

However, a significant concern arises from the output escaping analysis, where 0% of the 13 outputs are properly escaped. This represents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as unsanitized output can be injected with malicious scripts. The lack of capability checks and permission callbacks on the identified entry points (though currently zero) implies that if any were to be introduced in future versions, they might not be adequately secured. The absence of external HTTP requests and file operations is positive, but the lack of a robust attack surface doesn't negate the high risk posed by the unescaped output.

In conclusion, while the plugin demonstrates strong foundations by avoiding SQL injection and having a clean vulnerability history, the critical flaw in output escaping renders it insecure for user-facing functionality. The plugin would benefit from addressing the output escaping issues to mitigate XSS risks. The absence of other common vulnerabilities suggests good development practices in some areas, but the identified output escaping deficiency is a major weakness that requires immediate attention.

Key Concerns

  • Unescaped output
Vulnerabilities
None known

GNA Korean SNS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

GNA Korean SNS Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped13 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
render_tab1 (admin\gna-korean-sns-admin-settings-menu.php:63)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GNA Korean SNS Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuadmin\gna-korean-sns-admin-init.php:15
actionadmin_print_scriptsadmin\gna-korean-sns-admin-init.php:19
actionadmin_print_stylesadmin\gna-korean-sns-admin-init.php:20
actionadmin_initadmin\gna-korean-sns-admin-init.php:49
actioninitgna-korean-sns-core.php:22
filterplugin_row_metagna-korean-sns-core.php:23
Maintenance & Trust

GNA Korean SNS Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedSep 5, 2016
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

GNA Korean SNS Developer Profile

Chris Mok

13 plugins · 280 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GNA Korean SNS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gna-korean-sns/assets/css/gna-korean-sns-admin-styles.css

HTML / DOM Fingerprints

Data Attributes
gna-korean-sns-settings-menu
JS Globals
GNA_KoreanSNS_Admin_InitGNA_KoreanSNS
FAQ

Frequently Asked Questions about GNA Korean SNS