Meks Smart Social Widget Security & Risk Analysis

wordpress.org/plugins/meks-smart-social-widget

Easily display more than 100 social icons inside your WordPress widget.

10K active installs v1.6.5 PHP + WP 3.0+ Updated Jul 29, 2024
iconslinkedinredditsocialwidget
91
A · Safe
CVEs total4
Unpatched0
Last CVEApr 26, 2024
Safety Verdict

Is Meks Smart Social Widget Safe to Use in 2026?

Generally Safe

Score 91/100

Meks Smart Social Widget has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

4 known CVEsLast CVE: Apr 26, 2024Updated 1yr ago
Risk Assessment

The "meks-smart-social-widget" plugin v1.6.5 presents a mixed security profile. On the positive side, the static analysis reveals an exceptionally clean codebase with no identified dangerous functions, no file operations, no external HTTP requests, and a high percentage of properly escaped output. Furthermore, all SQL queries are properly prepared, and there are no identified taint flows, suggesting good coding practices in these areas.

However, a significant concern arises from the plugin's vulnerability history. The existence of 4 known medium-severity CVEs, with the most recent being in April 2024, indicates a recurring pattern of security weaknesses. The types of past vulnerabilities, including Cross-site Scripting (XSS), Missing Authorization, and Cross-Site Request Forgery (CSRF), are common and can have serious consequences if exploited. While there are currently no unpatched CVEs, the history suggests a need for diligent updates and thorough auditing of any new versions.

Despite the clean static analysis results for this specific version, the historical vulnerability data warrants caution. The absence of evident security controls like nonces or capability checks across its entry points (though the attack surface is reported as zero) could become a concern if new vulnerabilities are introduced. Therefore, while the current version appears to have mitigated direct exploitable code paths, the historical context necessitates a proactive approach to security for this plugin.

Key Concerns

  • History of 4 medium severity CVEs
  • Last vulnerability reported in April 2024
  • Common vulnerability types: XSS, Missing Auth, CSRF
  • No nonce checks observed
  • No capability checks observed
Vulnerabilities
4 published

Meks Smart Social Widget Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
4

4 total CVEs

CVE-2024-33693medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Meks Smart Social Widget <= 1.6.4 - Authenticated (Admin+) Stored Cross-Site Scripting

Apr 26, 2024 Patched in 1.6.5 (55d)
CVE-2024-0664medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Meks Smart Social Widget <= 1.6.3 - Authenticated (Admin+) Stored Cross-Site Scripting

Jan 26, 2024 Patched in 1.6.4 (186d)

Meks Smart Social Widget <= 1.6 - Missing Authorization to notice dimissal

Jul 27, 2023 Patched in 1.6.1 (180d)
CVE-2023-25989medium · 4.3Cross-Site Request Forgery (CSRF)

Meks Smart Social Widget <= 1.6 - Cross-Site Request Forgery via meks_remove_notification

Jul 26, 2023 Patched in 1.6.1 (181d)
Code Analysis
Analyzed Mar 16, 2026

Meks Smart Social Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
78 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped83 total outputs
Attack Surface

Meks Smart Social Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwp_enqueue_scriptsinc\class-social-widget.php:15
actionadmin_enqueue_scriptsinc\class-social-widget.php:16
filteruse_widgets_block_editorinc\class-social-widget.php:17
actionwidgets_initmeks-smart-social-widget.php:45
actionplugins_loadedmeks-smart-social-widget.php:53
Maintenance & Trust

Meks Smart Social Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 29, 2024
PHP min version
Downloads535K

Community Trust

Rating92/100
Number of ratings10
Active installs10K
Developer Profile

Meks Smart Social Widget Developer Profile

Meks

14 plugins · 117K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
236 days
View full developer profile
Detection Fingerprints

How We Detect Meks Smart Social Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/meks-smart-social-widget/css/style.css/wp-content/plugins/meks-smart-social-widget/js/main.js/wp-content/plugins/meks-smart-social-widget/css/admin.css
Script Paths
/wp-content/plugins/meks-smart-social-widget/js/main.js
Version Parameters
meks-smart-social-widget/css/style.css?ver=meks-smart-social-widget/js/main.js?ver=meks-smart-social-widget/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
mks_social_widgetmks_social_widget_ulsocicon-soc_
Data Attributes
data-id="mks_social_widget"
JS Globals
MKS_SOCIAL_WIDGET_URLMKS_SOCIAL_WIDGET_VER
Shortcode Output
<ul class="mks_social_widget_ul">
FAQ

Frequently Asked Questions about Meks Smart Social Widget