Showeblogin Social Plugin Security & Risk Analysis

wordpress.org/plugins/showeblogin-facebook-page-like-box

Brings the power of simplicity to display or embed Facebook Page Plugin widget into your WordPress website by using latest Graph API Version 22.0.

500 active installs v7.0 PHP 7.2.5+ WP 5.6+ Updated Feb 28, 2025
facebookfacebook-page-pluginfacebook-pluginfacebook-socialsocial-widget
70
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 4, 2025
Safety Verdict

Is Showeblogin Social Plugin Safe to Use in 2026?

Mostly Safe

Score 70/100

Showeblogin Social Plugin is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Apr 4, 2025Updated 1yr ago
Risk Assessment

The 'showeblogin-facebook-page-like-box' plugin version 7.0 presents a mixed security posture. While the static analysis reveals a limited attack surface with no unprotected entry points, no dangerous functions, and all SQL queries utilizing prepared statements, several areas raise concerns. A significant portion of output (78%) is not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the complete absence of nonce and capability checks on the single shortcode entry point is a critical oversight, allowing potential manipulation without proper authorization or validation.

The plugin's vulnerability history is particularly worrying, with one known medium-severity Cross-Site Scripting (XSS) vulnerability that is currently unpatched. The presence of XSS as a common vulnerability type, coupled with the high percentage of unescaped output identified in the static analysis, strongly suggests a recurring pattern of insecure handling of user-supplied or dynamic data. The unpatched CVE indicates that this specific risk remains present and exploitable in this version.

In conclusion, despite some good practices like prepared SQL statements, the significant amount of unescaped output and the critical lack of authorization/validation checks on its entry points, combined with an unpatched XSS vulnerability, make this plugin a considerable risk. Users should be highly cautious and prioritize patching or seeking an alternative until these issues are addressed.

Key Concerns

  • Unpatched CVE
  • High percentage of unescaped output
  • No nonce checks on shortcode
  • No capability checks on shortcode
Vulnerabilities
1

Showeblogin Social Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32169medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Showeblogin Social <= 7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 4, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Showeblogin Social Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
29
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

22% escaped37 total outputs
Attack Surface

Showeblogin Social Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[swt-fb-likebox] showeblogin-facebook-page-plugin.php:384
WordPress Hooks 4
actionadmin_noticesshoweblogin-facebook-page-plugin.php:56
actionwidgets_initshoweblogin-facebook-page-plugin.php:57
actionwp_enqueue_scriptsshoweblogin-facebook-page-plugin.php:58
actionadmin_enqueue_scriptsshoweblogin-facebook-page-plugin.php:59
Maintenance & Trust

Showeblogin Social Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 28, 2025
PHP min version7.2.5
Downloads53K

Community Trust

Rating98/100
Number of ratings50
Active installs500
Developer Profile

Showeblogin Social Plugin Developer Profile

Suresh Prasad

1 plugin · 500 total installs

73
trust score
Avg Security Score
70/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Showeblogin Social Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/showeblogin-facebook-page-like-box/css/style.css/wp-content/plugins/showeblogin-facebook-page-like-box/css/admin-style.css
Script Paths
//connect.facebook.net/%language%/sdk.js#xfbml=1&version=v22.0&appId=214112425590307&autoLogAppEvents=1
Version Parameters
showeblogin-facebook-page-like-box/css/style.css?ver=showeblogin-facebook-page-like-box/css/admin-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
showeblogin-widget-containerswt-fb-page-widgetswt-fb-page-widget-labelswt-fb-page-widget-content
HTML Comments
<!-- Showeblogin Social Plugin v7.0 - https://wordpress.org/plugins/showeblogin-facebook-page-like-box/ --><!-- Showeblogin Social Plugin HELP - https://www.superwebtricks.com/facebook-page-wordpress-plugin/ 28-02-2025 -->
Data Attributes
data-hrefdata-tabsdata-small-headerdata-adapt-container-widthdata-hide-ctadata-hide-cover+5 more
JS Globals
facebook-jssdk
Shortcode Output
<blockquote cite="https://www.superwebtricks.com/"><a href="https://www.superwebtricks.com/">SuperWebTricks</a> Loading...</blockquote>
FAQ

Frequently Asked Questions about Showeblogin Social Plugin