Seed Social Security & Risk Analysis

wordpress.org/plugins/seed-social

Minimal Social Sharing WordPress Plugin (Just Facebook, Twitter and Line)

7K active installs v2.0.6 PHP 5.3+ WP 4.5+ Updated Aug 6, 2024
facebooklinesharesocialtwitter
92
A · Safe
CVEs total1
Unpatched0
Last CVENov 9, 2022
Safety Verdict

Is Seed Social Safe to Use in 2026?

Generally Safe

Score 92/100

Seed Social has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 9, 2022Updated 1yr ago
Risk Assessment

The seed-social v2.0.6 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by having no external HTTP requests, no file operations, and all SQL queries utilizing prepared statements. The attack surface is also relatively small, with only one shortcode and no identified AJAX handlers or REST API routes that lack permission callbacks. Furthermore, there are no critical or high severity issues identified in the taint analysis, and no dangerous functions are used.

However, there are significant areas for concern. The plugin exhibits a low percentage of properly escaped output (27%), which strongly suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. This is corroborated by its vulnerability history, which shows one past medium severity XSS vulnerability. The absence of nonce checks and capability checks on entry points, despite the small attack surface, is also a notable weakness. While the current version might be patched against past vulnerabilities and the taint analysis shows no immediate critical flows, the consistent pattern of output-related vulnerabilities combined with a lack of basic security checks on its entry points indicates a persistent risk. The overall security is hindered by these oversight, requiring careful attention to output sanitization and access control.

Key Concerns

  • Low output escaping percentage
  • Missing nonce checks
  • Missing capability checks
  • Past medium severity XSS vulnerability
Vulnerabilities
1

Seed Social Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-3836medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Seed Social <= 2.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting

Nov 9, 2022 Patched in 2.0.4 (440d)
Code Analysis
Analyzed Mar 16, 2026

Seed Social Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

27% escaped33 total outputs
Attack Surface

Seed Social Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[seed_social] seed-social.php:317
WordPress Hooks 12
actionwp_headseed-social.php:66
actionwp_enqueue_scriptsseed-social.php:97
actionwp_footerseed-social.php:195
filterthe_contentseed-social.php:236
actionbbp_template_after_single_topicseed-social.php:256
actionbbp_template_before_single_topicseed-social.php:276
actionwoocommerce_after_single_productseed-social.php:293
actionwoocommerce_shareseed-social.php:309
actionadmin_menuseed-social.php:324
actionadmin_initseed-social.php:540
actionadd_meta_boxesseed-social.php:681
actionsave_postseed-social.php:707
Maintenance & Trust

Seed Social Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 6, 2024
PHP min version5.3
Downloads122K

Community Trust

Rating98/100
Number of ratings11
Active installs7K
Developer Profile

Seed Social Developer Profile

Seed Webs

3 plugins · 30K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
331 days
View full developer profile
Detection Fingerprints

How We Detect Seed Social

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/seed-social/style.css/wp-content/plugins/seed-social/script.js
Script Paths
/wp-content/plugins/seed-social/script.js
Version Parameters
seed-social/style.css?ver=2021.02seed-social/script.js?ver=2021.02

HTML / DOM Fingerprints

CSS Classes
seed-social-btnss-facebookss-twitterss-lineseed-social
Data Attributes
data-list="seed-social"
Shortcode Output
<ul data-list="seed-social" class="seed-social <li class="facebook"><li class="twitter"><li class="line">
FAQ

Frequently Asked Questions about Seed Social