
Open Graph Security & Risk Analysis
wordpress.org/plugins/opengraphAdds Open Graph metadata to your posts and pages so that they look great when shared on sites like Facebook and Twitter.
Is Open Graph Safe to Use in 2026?
Generally Safe
Score 99/100Open Graph has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the 'opengraph' plugin version 2.0.2 reveals a generally strong security posture. There are no identified dangerous functions, all SQL queries are properly prepared, and output is consistently escaped. The absence of file operations, external HTTP requests, and importantly, any detected taint flows with unsanitized paths, further indicates good coding practices. The attack surface is also reported as zero, meaning no direct entry points like AJAX handlers, REST API routes, or shortcodes were found to be exposed without proper authentication or permission checks.
However, the plugin's vulnerability history presents a significant concern. Despite the current clean slate in static analysis, there is one known CVE associated with this plugin. The fact that this CVE is marked as 'currently unpatched' and was last reported very recently (2024-06-04) suggests a potential for lingering vulnerabilities. The historical common vulnerability type being 'Exposure of Sensitive Information to an Unauthorized Actor' further emphasizes the need for vigilance, even if current code scans don't flag immediate threats. This suggests that past issues, though perhaps addressed in later versions not detailed here, have occurred, and the most recent reported vulnerability is still a concern.
In conclusion, while the code analysis for version 2.0.2 is highly positive, demonstrating robust security practices, the presence of a recently reported and unpatched CVE significantly lowers the overall security score. This indicates a strength in development hygiene but a weakness in timely vulnerability remediation. Users should be cautious and ensure they are on a version that has definitively addressed the known CVE.
Key Concerns
- Unpatched CVE exists
- Vulnerability history indicates past issues
Open Graph Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Open Graph <= 1.11.2 - Unauthenticated Sensitive Information Exposure
Open Graph Code Analysis
Output Escaping
Open Graph Attack Surface
WordPress Hooks 27
Maintenance & Trust
Open Graph Maintenance & Trust
Maintenance Signals
Community Trust
Open Graph Alternatives
Open Graph Pro
ogp
Adds Open Graph tags to your blog. Control how your posts and pages are presented on Facebook and other social media sites. No configuration needed.
Social Meta by Brozzme
wp-social-meta-by-brozzme
Add social meta for pages in header without coding.
OpenGraphMagic
opengraphmagic
OpenGraphMagic is a WordPress plugin that automatically generates images for Open Graph tags using external services like Pikwy and ScreenshotOne.
Simple Open Graph
simple-open-graph
Simple Open Graph adds Open Graph meta data to the header
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Open Graph Developer Profile
5 plugins · 11K total installs
How We Detect Open Graph
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/opengraph/opengraphopengraph/style.css?ver=opengraph/script.js?ver=