Shuuka Security & Risk Analysis

wordpress.org/plugins/shuuka-social-links

Your official identity. Everywhere. Embed your verified Shuuka profile on your WordPress site in minutes.

0 active installs v2.0.0 PHP 7.4+ WP 5.5+ Updated Mar 29, 2026
authenticationbio-linkofficial-identitysocial-linksverified-profile
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shuuka Safe to Use in 2026?

Generally Safe

Score 100/100

Shuuka has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "shuuka-social-links" plugin v1.0.0 presents a mixed security posture. On the positive side, there are no identified CVEs, no dangerous functions used, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests. This indicates a cautious approach to certain types of vulnerabilities. However, a significant concern arises from the complete lack of output escaping for all 42 identified outputs. This could lead to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website that are then executed by users' browsers.

The static analysis reveals no obvious attack surface in terms of AJAX handlers, REST API routes, shortcodes, or cron events. Taint analysis also shows no critical or high severity flows. The absence of vulnerability history further suggests that the plugin has not historically been a target or source of exploits. Despite these strengths, the pervasive lack of output escaping represents a fundamental security weakness that could be easily exploited. A balanced conclusion is that while the plugin avoids several common pitfalls, the lack of output sanitization is a critical oversight.

Key Concerns

  • All outputs are unescaped
Vulnerabilities
None known

Shuuka Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Shuuka Release Timeline

v2.0.0Current
Code Analysis
Analyzed Mar 17, 2026

Shuuka Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
42
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped42 total outputs
Attack Surface

Shuuka Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionredux/options/shuuka_user_page_setting/settings/changeshuuka-social-links.php:329
actionadmin_initshuuka-social-links.php:337
actionwp_enqueue_scriptsshuuka-social-links.php:373
actionwp_print_scriptsshuuka-social-links.php:384
actionwp_print_stylesshuuka-social-links.php:395
actioninitshuuka-social-links.php:409
Maintenance & Trust

Shuuka Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedMar 29, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Shuuka Developer Profile

Shuuka

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shuuka

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shuuka-social-links/assets/css/style.css/wp-content/plugins/shuuka-social-links/assets/js/main.js
Script Paths
/wp-content/plugins/shuuka-social-links/assets/js/main.js
Version Parameters
shuuka-social-links/assets/css/style.css?ver=shuuka-social-links/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
shuuka-social-links-container
HTML Comments
<!-- SHUUKA SOCIAL LINKS SHORTCODE --><!-- END SHUUKA SOCIAL LINKS SHORTCODE -->
Data Attributes
data-shuuka-slug
JS Globals
shuuka_plugin_url
Shortcode Output
<div class="shuuka-social-links-container" data-shuuka-slug="
FAQ

Frequently Asked Questions about Shuuka