
Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Security & Risk Analysis
wordpress.org/plugins/scrolling-twitter-like-google-plusone-linkedin-and-stumbleuponA very simple social share scrolling plugin with just 6 social icons (Twitter, FB Like, Google +1, Linkedin, FB Share and Stumbleupon)
Is Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Safe to Use in 2026?
Generally Safe
Score 85/100Scrolling Twitter Like Google +1 Linkedin and Stumbleupon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'scrolling-twitter-like-google-plusone-linkedin-and-stumbleupon' v1.0.2 presents a mixed security posture. From a static analysis perspective, it exhibits excellent practices regarding its limited attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and its use of prepared statements for SQL queries are positive indicators. However, a significant concern arises from the complete lack of output escaping. With 16 total outputs analyzed and 0% properly escaped, this represents a serious risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user interface.
The vulnerability history for this plugin is clean, with no recorded CVEs. This suggests a history of either good security practices or a lack of public scrutiny, which can be a double-edged sword. While the absence of past vulnerabilities is reassuring, it does not guarantee future security. The critical weakness identified through static analysis, namely the unescaped output, outweighs the positive aspects and the clean vulnerability history. This makes the plugin susceptible to XSS attacks, which can have severe consequences, including session hijacking and malware distribution.
In conclusion, while the plugin demonstrates strengths in minimizing its attack surface and secure database interaction, the complete failure to escape output is a critical vulnerability that significantly elevates its risk profile. Until this is addressed, the plugin should be considered insecure for production environments. The lack of vulnerability history is positive but does not mitigate the immediate risk posed by the unescaped output.
Key Concerns
- Unescaped output across all outputs
Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Security Vulnerabilities
Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Release Timeline
Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Code Analysis
Output Escaping
Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Attack Surface
WordPress Hooks 3
Maintenance & Trust
Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Maintenance & Trust
Maintenance Signals
Community Trust
Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Alternatives
Scrolling Social Sharebar (Twitter Like Google +1 Linkedin and Stumbleupon)
scrolling-social-sharebar
A scrolling social sharebar scrolling plugin with 7 social icons (Twitter, FB Like, Google +1, Linkedin, FB Share, Stumbleupon and Addthis) and option …
Floating Social Media Popout Buttons
floatingsocialmediapopout
Floating Social Media popout allows your webpage to show a face book like box and Googleplus badge widget when a visitor mouse hovers the floating face book icon or Googleplus icon located on right side of webpage.
Jamie Social Icons
jamie-social-icons
Share your posts & pages with your favourite social sites - Twitter, Facebook, Google Plus, Pinterest And LinkedIn and now trackable with your Goo …
Sharing is Caring
sharing-is-caring
Displays the social widgets from Facebook, Twitter, Google+ and Pinterest with your posts. Also adds some meta tags for opengraph and schema.org.
Business Badges
business-badges
Business Badges allows you to display customizable social badges on your website, like Google Business badge, facebook badge. Google+ badge Widget.
Scrolling Twitter Like Google +1 Linkedin and Stumbleupon Developer Profile
5 plugins · 100 total installs
How We Detect Scrolling Twitter Like Google +1 Linkedin and Stumbleupon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scrolling-twitter-like-google-plusone-linkedin-and-stumbleupon/css/style.css/wp-content/plugins/scrolling-twitter-like-google-plusone-linkedin-and-stumbleupon/js/social.jsscrolling-twitter-like-google-plusone-linkedin-and-stumbleupon/css/style.css?ver=scrolling-twitter-like-google-plusone-linkedin-and-stumbleupon/js/social.js?ver=HTML / DOM Fingerprints
scrollboxschildrensocialiconss<!-- Scrolling Twitter Like Google +1 Linkedin and Stumbleupon -->data-pin-urldata-pin-descriptiondata-pin-mediadata-pin-logdata-pin-numsocialsocialobjjQuery