Google Plus Badge Direct Connect Security & Risk Analysis

wordpress.org/plugins/google-badge-connect-direct-for-wordpress

Google+ badge allows visitors to directly connect with and promote your brand on Google+ from your website. Now you can add a Google+ badge to help yo …

10 active installs v1.1 PHP + WP 3.2+ Updated Nov 21, 2011
connect-directgoogle-connect-directgoogle-badgeseosocial-network
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Google Plus Badge Direct Connect Safe to Use in 2026?

Generally Safe

Score 85/100

Google Plus Badge Direct Connect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The plugin "google-badge-connect-direct-for-wordpress" version 1.1 exhibits a generally positive security posture based on the static analysis provided. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface, and importantly, all identified entry points are reportedly protected. The code also demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has no recorded vulnerabilities in its history. This indicates a mature and security-conscious development approach.

However, a critical concern arises from the output escaping analysis. With 100% of outputs not being properly escaped, this presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data rendered by the plugin could be manipulated by an attacker to inject malicious scripts, leading to session hijacking, credential theft, or defacement. While the plugin has no known vulnerabilities or a history of them, this unescaped output is a glaring weakness that needs immediate attention. The lack of demonstrated nonces and capability checks, though potentially acceptable given the limited attack surface, could become a liability if the plugin's functionality expands or if unescaped output is combined with other weaknesses.

In conclusion, while the plugin's low attack surface and secure SQL handling are commendable strengths, the pervasive lack of output escaping is a serious vulnerability. This single issue significantly overshadows the otherwise positive indicators. The absence of historical vulnerabilities is encouraging, but it does not mitigate the immediate risk posed by unescaped outputs. Addressing this XSS risk should be the highest priority.

Key Concerns

  • Outputs not properly escaped
Vulnerabilities
None known

Google Plus Badge Direct Connect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Google Plus Badge Direct Connect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped11 total outputs
Attack Surface

Google Plus Badge Direct Connect Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initgoogle_plus_badge_direct_connect.php:269
Maintenance & Trust

Google Plus Badge Direct Connect Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedNov 21, 2011
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Google Plus Badge Direct Connect Developer Profile

zzasha2007

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Google Plus Badge Direct Connect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://apis.google.com/js/plusone.js

HTML / DOM Fingerprints

CSS Classes
widget_GooglePlusBadgeDirectConnectWidget
HTML Comments
<!-- Place this tag where you want the badge to render-->
JS Globals
window.___gcfg
Shortcode Output
<g:plus
FAQ

Frequently Asked Questions about Google Plus Badge Direct Connect