
Populist Security & Risk Analysis
wordpress.org/plugins/populistTrack the popularity of your posts on social bookmarking sites reddit, stumbleupon, del.icio.us and digg
Is Populist Safe to Use in 2026?
Generally Safe
Score 100/100Populist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The populist plugin v1.5.1 presents a mixed security posture. While the static analysis shows a remarkably small attack surface with no apparent direct entry points like AJAX handlers, REST API routes, or shortcodes that are exposed without authentication, there are significant concerns within the code itself. The presence of two 'dangerous functions' (preg_replace with the /e modifier) and a complete lack of output escaping are particularly worrying. Taint analysis reveals two flows with unsanitized paths, indicating potential for command injection or other code execution vulnerabilities if these paths are reachable. The plugin's vulnerability history is clean, with no recorded CVEs. This could indicate good development practices or simply a lack of past scrutiny. However, the internal code signals, especially the lack of output escaping and the identified unsanitized flows, suggest that the plugin may have undiscovered vulnerabilities that could be exploited. Therefore, despite the absence of a known exploitable history, the internal code quality raises significant red flags.
Key Concerns
- Dangerous function: preg_replace(/e)
- Taint flow with unsanitized paths (High severity)
- Taint flow with unsanitized paths (High severity)
- 0% of output properly escaped
- 0 Nonce checks
- 0 Capability checks
Populist Security Vulnerabilities
Populist Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Populist Attack Surface
WordPress Hooks 1
Maintenance & Trust
Populist Maintenance & Trust
Maintenance Signals
Community Trust
Populist Alternatives
Social Buttons
social-buttons
Selectively add social network buttons to your posts, or theme design.
Tilt Social Share Widget
tilt-social-share-widget
Tilt Social Share Widget allows your users to quickly share your content on social sites. View "Description" tab for available services.
CMS Vote Up Social CMS News
cms-vote-up-social-cms-news-button
A must have social CMS website news button for Wordpress user (blogger). This button will enable your visitor to vote for your website's article …
DamnSexyBookmarks
damnsexybookmarks
Adds a social bookmarking menu to your posts/pages/index. Based on Josh Jones' SexyBookmarks plugin: http://eight7teen.com/sexy-bookmarks
notable
notable
Adds social bookmark links to each blog entry.
Populist Developer Profile
1 plugin · 10 total installs
How We Detect Populist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/populist/digg.php/wp-content/plugins/populist/delicious.php/wp-content/plugins/populist/reddit.php/wp-content/plugins/populist/stumble.php/wp-content/plugins/populist/goobl.php/wp-content/plugins/populist/yahoobl.php/wp-content/plugins/populist/functions.php/wp-content/plugins/populist/style.phpHTML / DOM Fingerprints
slmodulehndleinsidetabnavtab1tab2id="tabnav"id="gooblbox"id="yahblbox"id="diggbox"id="delbox"id="redbox"+1 more