
OpenGraphMagic Security & Risk Analysis
wordpress.org/plugins/opengraphmagicOpenGraphMagic is a WordPress plugin that automatically generates images for Open Graph tags using external services like Pikwy and ScreenshotOne.
Is OpenGraphMagic Safe to Use in 2026?
Generally Safe
Score 92/100OpenGraphMagic has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'opengraphmagic' v1.0.6 presents a generally good security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs and a clean vulnerability history are significant strengths, suggesting a history of responsible development and patching. Furthermore, the static analysis reveals a remarkably small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, which greatly limits potential entry points for attackers.
However, there are a few areas that warrant attention. The single SQL query identified is not using prepared statements, which represents a potential risk for SQL injection vulnerabilities, especially if any user-controlled input is ever incorporated into this query. While the output escaping is very high (92%), the remaining 8% of outputs could still be a vector for cross-site scripting (XSS) if unescaped outputs are handled insecurely. The presence of external HTTP requests, while not inherently risky, could become a concern if the plugin interacts with untrusted external resources without proper validation or sanitization.
In conclusion, 'opengraphmagic' v1.0.6 demonstrates strong security foundations with its limited attack surface and clean vulnerability record. The primary weaknesses lie in the single non-prepared SQL query and the minor percentage of unescaped output. Addressing these specific code signals would further enhance its security profile.
Key Concerns
- SQL queries not using prepared statements
- Minor percentage of unescaped output
OpenGraphMagic Security Vulnerabilities
OpenGraphMagic Code Analysis
SQL Query Safety
Output Escaping
OpenGraphMagic Attack Surface
WordPress Hooks 12
Maintenance & Trust
OpenGraphMagic Maintenance & Trust
Maintenance Signals
Community Trust
OpenGraphMagic Alternatives
Open Graph
opengraph
Adds Open Graph metadata to your posts and pages so that they look great when shared on sites like Facebook and Twitter.
Open Graph Pro
ogp
Adds Open Graph tags to your blog. Control how your posts and pages are presented on Facebook and other social media sites. No configuration needed.
Image SEO – AI-Driven Image SEO Optimizer
imageseo
Improve your images alt, title, captions and filenames for better SEO rankings.
Premmerce SEO for WooCommerce
woo-seo-addon
Premmerce SEO for WooCommerce plugin extends the functionality of WooCommerce microdata management.
Genesis Club Lite
genesis-club-lite
Mobile Responsive Logos, Hamburger Menus, Animated Top Bars, FAQ Accordions, User Signatures, Google Calendars and much more for Genesis sites
OpenGraphMagic Developer Profile
1 plugin · 10 total installs
How We Detect OpenGraphMagic
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/opengraphmagic/includes/js/opengraphmagic-admin.jsHTML / DOM Fingerprints
wrapdashicons-images-alt2id="clear-cache"