
Metro Style Social Widget Security & Risk Analysis
wordpress.org/plugins/metro-style-social-widgetMetro Style Social Network Widget
Is Metro Style Social Widget Safe to Use in 2026?
Generally Safe
Score 85/100Metro Style Social Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "metro-style-social-widget" plugin, version 1.0.2, exhibits a mixed security posture. On the positive side, there are no known CVEs associated with this plugin, and the code demonstrates a commitment to using prepared statements for SQL queries and avoiding file operations or external HTTP requests. The attack surface is also minimal, with no apparent AJAX handlers, REST API routes, shortcodes, or cron events, which reduces the potential entry points for attackers. However, significant concerns arise from the static analysis. The use of the `create_function` is a strong indicator of potential code injection vulnerabilities, as it can be exploited to execute arbitrary PHP code. Furthermore, the complete lack of output escaping across all 1501 identified output points is a critical flaw, making it highly susceptible to Cross-Site Scripting (XSS) attacks where user-supplied data is rendered directly to the browser without sanitization. The absence of nonce checks and capability checks, coupled with the `create_function` usage, further exacerbates these risks, as there are no mechanisms to verify user permissions or prevent unauthorized script execution.
While the plugin has no recorded vulnerability history, this can be misleading. The absence of historical vulnerabilities does not guarantee current security, especially given the glaring issues identified in the static analysis. The lack of proper output escaping and the presence of `create_function` are fundamental security weaknesses that could be exploited regardless of past incidents. The plugin's strengths lie in its limited attack surface and use of prepared statements for SQL, but these are overshadowed by critical vulnerabilities in code execution and output sanitization. A cautious approach is recommended, as the potential for XSS and code execution is substantial.
Key Concerns
- Use of create_function
- No output escaping
- No nonce checks
- No capability checks
Metro Style Social Widget Security Vulnerabilities
Metro Style Social Widget Code Analysis
Dangerous Functions Found
Output Escaping
Metro Style Social Widget Attack Surface
WordPress Hooks 6
Maintenance & Trust
Metro Style Social Widget Maintenance & Trust
Maintenance Signals
Community Trust
Metro Style Social Widget Alternatives
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Social Media Widget
social-media-widget
Adds links to all of your social media and sharing site profiles. Tons of icons come in 3 sizes, 4 icon styles, and 4 animations.
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)
miniorange-login-openid
Social Login with Discord, Facebook, Google, Twitter, LinkedIn and 40+ apps. Social login with social share and comments. Free, fast & easy! WooCo …
Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds
tagembed-widget
Collect & Embed Instagram Feed, Embed Facebook Feed, Embed YouTube Videos, Embed Twitter Feed, Google Reviews & 15+ Social Media Feed on website.
Optimize Social Share
heateor-open-graph-meta-tags
Optimizes social share by inserting Facebook Open Graph Meta Tags, General Meta Tags, Schema.org Meta Tags, Twitter Cards and Other Meta Tags in HTML …
Metro Style Social Widget Developer Profile
2 plugins · 390 total installs
How We Detect Metro Style Social Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/metro-style-social-widget/CSS/metro.cssmetro-style-social-widget/CSS/metro.css?ver=HTML / DOM Fingerprints
metro_style_social_widgetdata-default-colormetro-color-picker