Open Graph Security & Risk Analysis

wordpress.org/plugins/opengraph

Adds Open Graph metadata to your posts and pages so that they look great when shared on sites like Facebook and Twitter.

10K active installs v2.0.2 PHP + WP 2.3+ Updated Dec 7, 2025
facebookogpopengraphsocial
99
A · Safe
CVEs total1
Unpatched0
Last CVEJun 4, 2024
Safety Verdict

Is Open Graph Safe to Use in 2026?

Generally Safe

Score 99/100

Open Graph has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 4, 2024Updated 3mo ago
Risk Assessment

The static analysis of the 'opengraph' plugin version 2.0.2 reveals a generally strong security posture. There are no identified dangerous functions, all SQL queries are properly prepared, and output is consistently escaped. The absence of file operations, external HTTP requests, and importantly, any detected taint flows with unsanitized paths, further indicates good coding practices. The attack surface is also reported as zero, meaning no direct entry points like AJAX handlers, REST API routes, or shortcodes were found to be exposed without proper authentication or permission checks.

However, the plugin's vulnerability history presents a significant concern. Despite the current clean slate in static analysis, there is one known CVE associated with this plugin. The fact that this CVE is marked as 'currently unpatched' and was last reported very recently (2024-06-04) suggests a potential for lingering vulnerabilities. The historical common vulnerability type being 'Exposure of Sensitive Information to an Unauthorized Actor' further emphasizes the need for vigilance, even if current code scans don't flag immediate threats. This suggests that past issues, though perhaps addressed in later versions not detailed here, have occurred, and the most recent reported vulnerability is still a concern.

In conclusion, while the code analysis for version 2.0.2 is highly positive, demonstrating robust security practices, the presence of a recently reported and unpatched CVE significantly lowers the overall security score. This indicates a strength in development hygiene but a weakness in timely vulnerability remediation. Users should be cautious and ensure they are on a version that has definitively addressed the known CVE.

Key Concerns

  • Unpatched CVE exists
  • Vulnerability history indicates past issues
Vulnerabilities
1

Open Graph Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-5615medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

Open Graph <= 1.11.2 - Unauthenticated Sensitive Information Exposure

Jun 4, 2024 Patched in 1.11.3 (2d)
Code Analysis
Analyzed Mar 16, 2026

Open Graph Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped8 total outputs
Attack Surface

Open Graph Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 27
filterjetpack_enable_opengraphopengraph.php:18
filterjetpack_enable_open_graphopengraph.php:19
filterlanguage_attributesopengraph.php:56
filteropengraph_titleopengraph.php:161
filteropengraph_typeopengraph.php:162
filteropengraph_urlopengraph.php:163
filteropengraph_imageopengraph.php:166
filteropengraph_imageopengraph.php:167
filteropengraph_imageopengraph.php:168
filteropengraph_imageopengraph.php:169
filteropengraph_imageopengraph.php:170
filteropengraph_imageopengraph.php:171
filteropengraph_descriptionopengraph.php:173
filteropengraph_localeopengraph.php:174
filteropengraph_site_nameopengraph.php:175
filteropengraph_audioopengraph.php:176
filteropengraph_videoopengraph.php:177
filteropengraph_prefixesopengraph.php:180
filteropengraph_metadataopengraph.php:183
filteropengraph_metadataopengraph.php:186
filtertwitter_cardopengraph.php:189
filtertwitter_creatoropengraph.php:190
filterfediverse_creatoropengraph.php:193
actionwpopengraph.php:195
actionwp_headopengraph.php:801
filteruser_contactmethodsopengraph.php:885
filtersite_icon_image_sizesopengraph.php:900
Maintenance & Trust

Open Graph Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 7, 2025
PHP min version
Downloads219K

Community Trust

Rating86/100
Number of ratings13
Active installs10K
Developer Profile

Open Graph Developer Profile

Will Norris

5 plugins · 11K total installs

96
trust score
Avg Security Score
94/100
Avg Patch Time
2 days
View full developer profile
Detection Fingerprints

How We Detect Open Graph

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/opengraph/
Generator Patterns
opengraph
Version Parameters
opengraph/style.css?ver=opengraph/script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Open Graph