Itmaroon Social Post Sync Security & Risk Analysis

wordpress.org/plugins/itmaroon-social-post-sync

This plugin synchronizes WordPress posts with social media (X, Facebook, Instagram) using an AWS-based backend system.

0 active installs v1.0.0 PHP 8.2+ WP 6.4+ Updated Unknown
facebookinstagramsnssocialx
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Itmaroon Social Post Sync Safe to Use in 2026?

Generally Safe

Score 100/100

Itmaroon Social Post Sync has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'itmaroon-social-post-sync' v1.0.0 plugin exhibits a generally good security posture with several strengths. The absence of known CVEs and critical taint flows is a significant positive. Furthermore, the plugin demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its output. The presence of nonce and capability checks, while only one capability check is noted, are also good indicators of security awareness. However, there are notable areas of concern. The plugin exposes two AJAX handlers without authentication checks, creating a direct attack vector for unauthenticated users. While the attack surface is relatively small, these unprotected entry points represent a tangible risk. The plugin also makes a large number of external HTTP requests, which, while not inherently a vulnerability, could be a target for various attacks if not handled securely, especially if the data being sent or received is sensitive or if there are vulnerabilities in the external services themselves.

In conclusion, the plugin's foundation is solid, with good practices in place for database interactions and output handling, and no prior history of vulnerabilities. The primary weakness lies in the unprotected AJAX endpoints, which require immediate attention to mitigate potential unauthorized actions. The high number of external HTTP requests warrants careful review to ensure proper sanitization and security measures are in place for each request, though this is more of a potential area for improvement than an immediate vulnerability based on the provided data. Overall, the plugin is reasonably secure but could be significantly improved by addressing the unauthenticated AJAX handlers.

Key Concerns

  • Unprotected AJAX handlers
Vulnerabilities
None known

Itmaroon Social Post Sync Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Itmaroon Social Post Sync Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
176 escaped
Nonce Checks
11
Capability Checks
1
File Operations
5
External Requests
36
Bundled Libraries
0

Output Escaping

93% escaped190 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<itmaroon-social-post-sync> (itmaroon-social-post-sync.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Itmaroon Social Post Sync Attack Surface

Entry Points18
Unprotected2

AJAX Handlers 16

authwp_ajax_itmar_option_entryitmaroon-social-post-sync.php:991
authwp_ajax_itmar_del_pendingitmaroon-social-post-sync.php:1011
authwp_ajax_itmar_url_transitmaroon-social-post-sync.php:1048
noprivwp_ajax_itmar_url_transitmaroon-social-post-sync.php:1049
authwp_ajax_itmar_get_imgUrlitmaroon-social-post-sync.php:1115
noprivwp_ajax_itmar_get_imgUrlitmaroon-social-post-sync.php:1116
authwp_ajax_itmar_del_snsitmaroon-social-post-sync.php:1233
authwp_ajax_noprivitmar__del_snsitmaroon-social-post-sync.php:1234
authwp_ajax_itmar_entry_snsitmaroon-social-post-sync.php:1279
noprivwp_ajax_itmar_entry_snsitmaroon-social-post-sync.php:1280
authwp_ajax_itmar_get_snsitmaroon-social-post-sync.php:1532
noprivwp_ajax_itmar_get_snsitmaroon-social-post-sync.php:1533
authwp_ajax_itmar_get_idsitmaroon-social-post-sync.php:1574
noprivwp_ajax_itmar_get_idsitmaroon-social-post-sync.php:1575
authwp_ajax_itmar_post_ajaxitmaroon-social-post-sync.php:1647
noprivwp_ajax_itmar_post_ajaxitmaroon-social-post-sync.php:1648

REST API Routes 2

POST/wp-json/itmar-sns/v1/receive_facebook_tokensrc\Facebook\TokenReceiver.php:20
POST/wp-json/itmar-sns/v1/receive_twitter_tokensrc\Twitter\TokenReceiver.php:17
WordPress Hooks 8
actionadmin_menuitmaroon-social-post-sync.php:47
actionplugins_loadeditmaroon-social-post-sync.php:102
actionadmin_inititmaroon-social-post-sync.php:108
actionadmin_enqueue_scriptsitmaroon-social-post-sync.php:121
filterget_post_metadataitmaroon-social-post-sync.php:1382
filterget_post_metadataitmaroon-social-post-sync.php:1466
actionrest_api_initsrc\Facebook\TokenReceiver.php:15
actionrest_api_initsrc\Twitter\TokenReceiver.php:12
Maintenance & Trust

Itmaroon Social Post Sync Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version8.2
Downloads124

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Itmaroon Social Post Sync Developer Profile

Isamu Takeda

9 plugins · 50 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Itmaroon Social Post Sync

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/itmaroon-social-post-sync/assets/vendor/swiper-12.0.1/swiper-bundle.min.css/wp-content/plugins/itmaroon-social-post-sync/assets/vendor/jquery-datetimepicker-2.5.21/jquery.datetimepicker.min.css/wp-content/plugins/itmaroon-social-post-sync/css/sns_style.css/wp-content/plugins/itmaroon-social-post-sync/css/sns_common.css/wp-content/plugins/itmaroon-social-post-sync/assets/vendor/swiper-12.0.1/swiper-bundle.min.js/wp-content/plugins/itmaroon-social-post-sync/assets/vendor/imagesloaded-5.0.0/imagesloaded.pkgd.min.js/wp-content/plugins/itmaroon-social-post-sync/assets/vendor/jquery-easing-1.4.1/jquery.easing.min.js/wp-content/plugins/itmaroon-social-post-sync/assets/vendor/jquery-datetimepicker-2.5.21/jquery.datetimepicker.full.min.js+1 more
Script Paths
assets/vendor/swiper-12.0.1/swiper-bundle.min.jsassets/vendor/imagesloaded-5.0.0/imagesloaded.pkgd.min.jsassets/vendor/jquery-easing-1.4.1/jquery.easing.min.jsassets/vendor/jquery-datetimepicker-2.5.21/jquery.datetimepicker.full.min.jsjs/sns_common.js
Version Parameters
itmaroon-social-post-sync/assets/vendor/swiper-12.0.1/swiper-bundle.min.css?ver=itmaroon-social-post-sync/assets/vendor/jquery-datetimepicker-2.5.21/jquery.datetimepicker.min.css?ver=itmaroon-social-post-sync/css/sns_style.css?ver=itmaroon-social-post-sync/css/sns_common.css?ver=itmaroon-social-post-sync/assets/vendor/swiper-12.0.1/swiper-bundle.min.js?ver=itmaroon-social-post-sync/assets/vendor/imagesloaded-5.0.0/imagesloaded.pkgd.min.js?ver=itmaroon-social-post-sync/assets/vendor/jquery-easing-1.4.1/jquery.easing.min.js?ver=itmaroon-social-post-sync/assets/vendor/jquery-datetimepicker-2.5.21/jquery.datetimepicker.full.min.js?ver=itmaroon-social-post-sync/js/sns_common.js?ver=

HTML / DOM Fingerprints

CSS Classes
sns-relate-loginpage_titlesp-onlycommand_areawork_content_titlecommand_listcmd_btnlogin+3 more
HTML Comments
<!-- /.page_title --><!-- /.work_content_title --><!-- /.command_item -->
Data Attributes
data-*
JS Globals
sns_relate_ajax_object
FAQ

Frequently Asked Questions about Itmaroon Social Post Sync