
Showeblogin Social Plugin Security & Risk Analysis
wordpress.org/plugins/showeblogin-facebook-page-like-boxBrings the power of simplicity to display or embed Facebook Page Plugin widget into your WordPress website by using latest Graph API Version 22.0.
Is Showeblogin Social Plugin Safe to Use in 2026?
Mostly Safe
Score 70/100Showeblogin Social Plugin is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The 'showeblogin-facebook-page-like-box' plugin version 7.0 presents a mixed security posture. While the static analysis reveals a limited attack surface with no unprotected entry points, no dangerous functions, and all SQL queries utilizing prepared statements, several areas raise concerns. A significant portion of output (78%) is not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the complete absence of nonce and capability checks on the single shortcode entry point is a critical oversight, allowing potential manipulation without proper authorization or validation.
The plugin's vulnerability history is particularly worrying, with one known medium-severity Cross-Site Scripting (XSS) vulnerability that is currently unpatched. The presence of XSS as a common vulnerability type, coupled with the high percentage of unescaped output identified in the static analysis, strongly suggests a recurring pattern of insecure handling of user-supplied or dynamic data. The unpatched CVE indicates that this specific risk remains present and exploitable in this version.
In conclusion, despite some good practices like prepared SQL statements, the significant amount of unescaped output and the critical lack of authorization/validation checks on its entry points, combined with an unpatched XSS vulnerability, make this plugin a considerable risk. Users should be highly cautious and prioritize patching or seeking an alternative until these issues are addressed.
Key Concerns
- Unpatched CVE
- High percentage of unescaped output
- No nonce checks on shortcode
- No capability checks on shortcode
Showeblogin Social Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Showeblogin Social <= 7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Showeblogin Social Plugin Code Analysis
Output Escaping
Showeblogin Social Plugin Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Showeblogin Social Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Showeblogin Social Plugin Alternatives
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Mongoose Page Plugin
facebook-page-feed-graph-api
The most popular way to display the Facebook Page Plugin on your WordPress website. Easy implementation using a shortcode or widget.
Fan Page Widget by ThemeNcode
facebook-fan-page-widget
An widget that will display Facebook Fan page like box. Uses latest API of Facebook (v 16.0)
Metro Style Social Widget
metro-style-social-widget
Metro Style Social Network Widget
WPB Social Master
wpb-social-master
This plugin will add responsive social share & follow icons. Very easy to use, just put a shortcode.
Showeblogin Social Plugin Developer Profile
1 plugin · 500 total installs
How We Detect Showeblogin Social Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/showeblogin-facebook-page-like-box/css/style.css/wp-content/plugins/showeblogin-facebook-page-like-box/css/admin-style.css//connect.facebook.net/%language%/sdk.js#xfbml=1&version=v22.0&appId=214112425590307&autoLogAppEvents=1showeblogin-facebook-page-like-box/css/style.css?ver=showeblogin-facebook-page-like-box/css/admin-style.css?ver=HTML / DOM Fingerprints
showeblogin-widget-containerswt-fb-page-widgetswt-fb-page-widget-labelswt-fb-page-widget-content<!-- Showeblogin Social Plugin v7.0 - https://wordpress.org/plugins/showeblogin-facebook-page-like-box/ --><!-- Showeblogin Social Plugin HELP - https://www.superwebtricks.com/facebook-page-wordpress-plugin/ 28-02-2025 -->data-hrefdata-tabsdata-small-headerdata-adapt-container-widthdata-hide-ctadata-hide-cover+5 morefacebook-jssdk<blockquote cite="https://www.superwebtricks.com/"><a href="https://www.superwebtricks.com/">SuperWebTricks</a> Loading...</blockquote>