
showGplus Security & Risk Analysis
wordpress.org/plugins/showgplusA small plugin whose purpose is to show G+ "Follow us", using a shortcode.
Is showGplus Safe to Use in 2026?
Generally Safe
Score 85/100showGplus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'showgplus' v1.01 plugin exhibits a generally strong security posture based on the provided static analysis. There are no detected dangerous functions, all SQL queries utilize prepared statements, and all outputs are properly escaped. Furthermore, the plugin has no recorded vulnerability history, indicating a lack of publicly known exploits. This suggests the developers have followed good security practices in its implementation.
However, the analysis does reveal some areas for caution. The plugin lacks any nonce checks and capability checks, which is a significant concern. While the current attack surface is small and has no unprotected entry points detected, the absence of these fundamental security mechanisms means that if new entry points were introduced or existing ones were to become vulnerable, there would be no built-in protection against unauthorized actions. The taint analysis also shows no flows, but this could be due to the limited scope of the analysis or the lack of complex input handling, rather than an inherent absence of risk.
In conclusion, 'showgplus' v1.01 appears to be well-developed from a code hygiene perspective, with no exploitable vulnerabilities flagged in the static analysis or history. The primary weakness lies in the absence of crucial authorization checks (nonces and capabilities). While the risk is currently mitigated by a small and seemingly secured attack surface, this oversight represents a potential future vulnerability if the plugin's functionality or interaction with WordPress evolves.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
showGplus Security Vulnerabilities
showGplus Code Analysis
showGplus Attack Surface
Shortcodes 1
Maintenance & Trust
showGplus Maintenance & Trust
Maintenance Signals
Community Trust
showGplus Alternatives
Social Comments
social-comments
This plugin adds Google Plus Comments system, Facebook comments and / or Disqus Comments to your site.
GP – GeePress
gp
All the tools you need to integrate your WordPress and Google+.
Strx Simple Sharing Sidebar Widget
strx-simple-sharing-sidebar-widget
Dynamic widget to insert classic social buttons and counters on your sidebar.
SEO Friendly Images
seo-image
SEO Friendly Images automatically adds alt and title attributes to all your images improving traffic from search engines.
Admin Custom Font
admin-custom-font
Admin Custom Font plugin allows you to replace default/factory font in WordPress Admin Dashboard with hundreds of different Google Fonts.
showGplus Developer Profile
3 plugins · 30 total installs
How We Detect showGplus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/showgplus/style.csshttps://apis.google.com/js/plusone.jsshowgplus/style.css?ver=HTML / DOM Fingerprints
g-plusdata-widthdata-heightdata-hrefdata-relwindow.__gcfg<div class="g-plus" data-width= data-height= data-href= data-rel="publisher"></div>