Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Security & Risk Analysis

wordpress.org/plugins/scrolling-twitter-like-google-plusone-linkedin-and-stumbleupon

A very simple social share scrolling plugin with just 6 social icons (Twitter, FB Like, Google +1, Linkedin, FB Share and Stumbleupon)

10 active installs v1.0.2 PHP + WP 3.0+ Updated Aug 9, 2011
facebookgooglelikesimple-social-sharesocial-share
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Safe to Use in 2026?

Generally Safe

Score 85/100

Scrolling Twitter Like Google +1 Linkedin and Stumbleupon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The plugin 'scrolling-twitter-like-google-plusone-linkedin-and-stumbleupon' v1.0.2 presents a mixed security posture. From a static analysis perspective, it exhibits excellent practices regarding its limited attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and its use of prepared statements for SQL queries are positive indicators. However, a significant concern arises from the complete lack of output escaping. With 16 total outputs analyzed and 0% properly escaped, this represents a serious risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user interface.

The vulnerability history for this plugin is clean, with no recorded CVEs. This suggests a history of either good security practices or a lack of public scrutiny, which can be a double-edged sword. While the absence of past vulnerabilities is reassuring, it does not guarantee future security. The critical weakness identified through static analysis, namely the unescaped output, outweighs the positive aspects and the clean vulnerability history. This makes the plugin susceptible to XSS attacks, which can have severe consequences, including session hijacking and malware distribution.

In conclusion, while the plugin demonstrates strengths in minimizing its attack surface and secure database interaction, the complete failure to escape output is a critical vulnerability that significantly elevates its risk profile. Until this is addressed, the plugin should be considered insecure for production environments. The lack of vulnerability history is positive but does not mitigate the immediate risk posed by the unescaped output.

Key Concerns

  • Unescaped output across all outputs
Vulnerabilities
None known

Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Release Timeline

v1.0.2Current
v1.0.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped16 total outputs
Attack Surface

Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menusocialscroll.php:195
actionwp_headsocialscroll.php:196
filterthe_contentsocialscroll.php:197
Maintenance & Trust

Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedAug 9, 2011
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Developer Profile

sudipto

5 plugins · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Scrolling Twitter Like Google +1 Linkedin and Stumbleupon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/scrolling-twitter-like-google-plusone-linkedin-and-stumbleupon/css/style.css
Script Paths
/wp-content/plugins/scrolling-twitter-like-google-plusone-linkedin-and-stumbleupon/js/social.js
Version Parameters
scrolling-twitter-like-google-plusone-linkedin-and-stumbleupon/css/style.css?ver=scrolling-twitter-like-google-plusone-linkedin-and-stumbleupon/js/social.js?ver=

HTML / DOM Fingerprints

CSS Classes
scrollboxschildrensocialiconss
HTML Comments
<!-- Scrolling Twitter Like Google +1 Linkedin and Stumbleupon -->
Data Attributes
data-pin-urldata-pin-descriptiondata-pin-mediadata-pin-logdata-pin-num
JS Globals
socialsocialobjjQuery
FAQ

Frequently Asked Questions about Scrolling Twitter Like Google +1 Linkedin and Stumbleupon