Opengraph and Microdata Generator Security & Risk Analysis

wordpress.org/plugins/opengraph-and-microdata-generator

Adds Facebook OpenGraph Meta Tags to head for a better social sharing experience.

50 active installs v3.4 PHP + WP 3.0+ Updated Nov 24, 2012
facebookopen-graphopengraphschemaschema-microdata
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Opengraph and Microdata Generator Safe to Use in 2026?

Generally Safe

Score 85/100

Opengraph and Microdata Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "opengraph-and-microdata-generator" plugin v3.4 exhibits a generally strong security posture in several key areas. Static analysis reveals no AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a remarkably small attack surface with no apparent unprotected entry points. Furthermore, the plugin demonstrates excellent SQL hygiene, with all queries utilizing prepared statements, and a complete absence of file operations, external HTTP requests, and bundled libraries, which are common vectors for vulnerabilities.

However, a significant concern emerges from the output escaping analysis, where 100% of the eight identified outputs are not properly escaped. This lack of sanitization presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the context of a user's browser. Despite the absence of known CVEs and a clean vulnerability history, this single code signal is a critical weakness that requires immediate attention.

In conclusion, while the plugin excels in limiting its attack surface and managing database interactions securely, the universal failure to escape output creates a substantial XSS risk. The lack of any recorded historical vulnerabilities might suggest either a fortunate oversight or a limited attack history, but it does not negate the present danger posed by unescaped output. Addressing the output escaping issue is paramount to mitigating this risk.

Key Concerns

  • Unescaped output found
Vulnerabilities
None known

Opengraph and Microdata Generator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Opengraph and Microdata Generator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

Opengraph and Microdata Generator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuopengraph-microdata.php:29
actionadmin_initopengraph-microdata.php:30
actionwp_headopengraph-microdata.php:279
Maintenance & Trust

Opengraph and Microdata Generator Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedNov 24, 2012
PHP min version
Downloads13K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

Opengraph and Microdata Generator Developer Profile

Abhik

3 plugins · 170 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Opengraph and Microdata Generator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/opengraph-and-microdata-generator/js/opengraph-microdata.js
Script Paths
/wp-content/plugins/opengraph-and-microdata-generator/js/opengraph-microdata.js

HTML / DOM Fingerprints

CSS Classes
wrappostboxhndle
Data Attributes
name="wpogmcappid"name="wpogmcadminid"name="wpogmcthumbnail"name="wpogmclocale"name="wpogmcwordlimit"
FAQ

Frequently Asked Questions about Opengraph and Microdata Generator