GRA4 Social Network Security & Risk Analysis

wordpress.org/plugins/gra4-social-network

Social Network for WordPress will keep the users on your website by entertaining them with social networking functionality (friends, likes, activity, …

10 active installs v0.0.5.7 PHP + WP 3.3+ Updated Feb 4, 2014
communitylikesnetworknetworkingsocial
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GRA4 Social Network Safe to Use in 2026?

Generally Safe

Score 85/100

GRA4 Social Network has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "gra4-social-network" plugin version 0.0.5.7 presents a mixed security posture. On the positive side, there are no known historical vulnerabilities (CVEs) associated with this plugin, suggesting a potentially stable codebase. Furthermore, the static analysis indicates a limited attack surface with no AJAX handlers or REST API routes directly exposed without authentication. The absence of critical or high-severity taint flows is also a good sign, implying that potentially malicious data is not being mishandled in a way that immediately suggests high-risk vulnerabilities.

However, several concerning patterns emerge from the code analysis. A significant weakness lies in the output escaping, with only 2% of outputs being properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the lack of nonce checks and capability checks for any entry points is a major security oversight, leaving the plugin susceptible to Cross-Site Request Forgery (CSRF) and unauthorized actions. The presence of raw SQL queries without prepared statements also raises concerns about potential SQL injection vulnerabilities, especially when combined with the lack of proper sanitization for file operations, as evidenced by the taint analysis showing flows with unsanitized paths.

While the plugin has no recorded vulnerability history, this is not a guarantee of future security, especially given the identified code weaknesses. The lack of proper sanitization and escaping, coupled with the absence of robust authentication checks for its entry points, creates a fertile ground for attacks. The plugin should be thoroughly reviewed and remediated to address these significant security gaps.

Key Concerns

  • Unescaped output (2% properly escaped)
  • No nonce checks
  • No capability checks
  • SQL queries not fully prepared (25% prepared)
  • Flows with unsanitized paths
Vulnerabilities
None known

GRA4 Social Network Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

GRA4 Social Network Release Timeline

v0.0.5.7Current
v0.0.5.6
v0.0.5.5
v0.0.5.4
v0.0.5.3
v0.0.5.2
v0.0.5.1
v0.0.5.0
v0.0.4.9
v0.0.4.8
v0.0.4.7
v0.0.4.6
v0.0.4.5
v0.0.4.4
v0.0.4.3
v0.0.4.2
v0.0.4.1
v0.0.4.0
v0.0.3.9
v0.0.3.8
Code Analysis
Analyzed Mar 17, 2026

GRA4 Social Network Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
1 prepared
Unescaped Output
47
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
31
External Requests
2
Bundled Libraries
0

SQL Query Safety

25% prepared4 total queries

Output Escaping

2% escaped48 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
admin_option_page (gra4.php:272)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GRA4 Social Network Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[GRA4_CONTENT] gra4.php:133
WordPress Hooks 12
actioninitgra4.php:126
filterupgrader_pre_installgra4.php:128
filterupgrader_post_installgra4.php:129
filterrewrite_rules_arraygra4.php:135
actionadmin_menugra4.php:138
filterplugin_action_linksgra4.php:140
actionadmin_bar_menugra4.php:143
actionwp_print_scriptsgra4.php:166
filterthe_contentgra4.php:167
filterjetpack_enable_opengraphgra4.php:169
filterjetpack_enable_open_graphgra4.php:170
filterthe_contentgra4.php:1267
Maintenance & Trust

GRA4 Social Network Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedFeb 4, 2014
PHP min version
Downloads21K

Community Trust

Rating76/100
Number of ratings10
Active installs10
Developer Profile

GRA4 Social Network Developer Profile

Matthew Petroff

16 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GRA4 Social Network

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gra4-social-network/gra4.css/wp-content/plugins/gra4-social-network/gra4.js/wp-content/plugins/gra4-social-network/admin/gra4_admin.css/wp-content/plugins/gra4-social-network/admin/gra4_admin.js/wp-content/plugins/gra4-social-network/js/jquery.flexslider.js/wp-content/plugins/gra4-social-network/js/jquery.autosize.min.js/wp-content/plugins/gra4-social-network/js/gra4_search.js/wp-content/plugins/gra4-social-network/js/gra4_profile.js+12 more
Script Paths
/wp-content/plugins/gra4-social-network/gra4.js/wp-content/plugins/gra4-social-network/admin/gra4_admin.js/wp-content/plugins/gra4-social-network/js/jquery.flexslider.js/wp-content/plugins/gra4-social-network/js/jquery.autosize.min.js/wp-content/plugins/gra4-social-network/js/gra4_search.js/wp-content/plugins/gra4-social-network/js/gra4_profile.js+12 more
Version Parameters
gra4-social-network/gra4.css?ver=gra4-social-network/gra4.js?ver=gra4-social-network/admin/gra4_admin.css?ver=gra4-social-network/admin/gra4_admin.js?ver=gra4-social-network/js/jquery.flexslider.js?ver=gra4-social-network/js/jquery.autosize.min.js?ver=gra4-social-network/js/gra4_search.js?ver=gra4-social-network/js/gra4_profile.js?ver=gra4-social-network/js/gra4_activity.js?ver=gra4-social-network/js/gra4_messages.js?ver=gra4-social-network/js/gra4_friends.js?ver=gra4-social-network/js/gra4_groups.js?ver=gra4-social-network/js/gra4_friends_find.js?ver=gra4-social-network/js/gra4_search_friend.js?ver=gra4-social-network/js/gra4_post_comment.js?ver=gra4-social-network/js/gra4_groups_find.js?ver=gra4-social-network/js/gra4_wall.js?ver=gra4-social-network/js/gra4_wall_comment.js?ver=gra4-social-network/js/gra4_groups_wall.js?ver=gra4-social-network/js/gra4_groups_wall_comment.js?ver=

HTML / DOM Fingerprints

CSS Classes
gra4-friends-profile-cardgra4-groups-profile-cardgra4_profile_photogra4_profile_namegra4_profile_statusgra4_profile_locationgra4_profile_last_onlinegra4_photo_link+32 more
HTML Comments
GRA4 Social NetworkGRA4 may send headers out - so we prevent warningGRA4 supplies the dynamic content even for non-logged visitors.Therefore we try to switch off caching for the GRA4 pages+4 more
Data Attributes
data-gra4-user-iddata-gra4-post-iddata-gra4-comment-iddata-gra4-group-iddata-gra4-friend-iddata-gra4-message-id+2 more
JS Globals
gra4_paramsGRA4_versiongra4_current_user_id
Shortcode Output
[GRA4_CONTENT]
FAQ

Frequently Asked Questions about GRA4 Social Network