
Simple Follow Buttons Security & Risk Analysis
wordpress.org/plugins/simple-follow-buttonsA simple plugin that enables you to add follow buttons to all of your posts and/or pages.
Is Simple Follow Buttons Safe to Use in 2026?
Generally Safe
Score 85/100Simple Follow Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simple-follow-buttons" plugin version 1.0.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by using prepared statements for all SQL queries, implementing nonce checks, and performing capability checks. It also has a clean vulnerability history with no recorded CVEs, suggesting a relatively stable codebase. The attack surface is limited to two shortcodes, and there are no AJAX handlers or REST API routes without authentication checks. However, significant concerns arise from the static analysis. The presence of the `create_function` dangerous function is a red flag, as it can be exploited for code injection if not handled with extreme care, although the provided data doesn't indicate any direct exploitation paths for it. More critically, 100% of the output escaping is improperly handled. This means that any data displayed by the plugin, especially if it originates from user input or external sources, could be vulnerable to cross-site scripting (XSS) attacks. The lack of taint analysis results is unusual and may indicate that the analysis tools were unable to fully trace data flows, which in itself can be a point of concern if it masks potential vulnerabilities.
In conclusion, while the plugin avoids common pitfalls like direct SQL injection and has no known vulnerabilities, the complete lack of proper output escaping is a severe weakness that leaves it highly susceptible to XSS attacks. The use of `create_function` is also a concern that warrants investigation. The limited attack surface and absence of critical taint flows are strengths, but they are overshadowed by the high risk of XSS due to the unescaped outputs.
Key Concerns
- 100% of outputs are not properly escaped
- Dangerous function 'create_function' found
Simple Follow Buttons Security Vulnerabilities
Simple Follow Buttons Code Analysis
Dangerous Functions Found
Output Escaping
Simple Follow Buttons Attack Surface
Shortcodes 2
WordPress Hooks 8
Maintenance & Trust
Simple Follow Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Simple Follow Buttons Alternatives
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Social Media Widget
social-media-widget
Adds links to all of your social media and sharing site profiles. Tons of icons come in 3 sizes, 4 icon styles, and 4 animations.
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)
miniorange-login-openid
Social Login with Discord, Facebook, Google, Twitter, LinkedIn and 40+ apps. Social login with social share and comments. Free, fast & easy! WooCo …
Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds
tagembed-widget
Collect & Embed Instagram Feed, Embed Facebook Feed, Embed YouTube Videos, Embed Twitter Feed, Google Reviews & 15+ Social Media Feed on website.
Optimize Social Share
heateor-open-graph-meta-tags
Optimizes social share by inserting Facebook Open Graph Meta Tags, General Meta Tags, Schema.org Meta Tags, Twitter Cards and Other Meta Tags in HTML …
Simple Follow Buttons Developer Profile
3 plugins · 40K total installs
How We Detect Simple Follow Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-follow-buttons/css/readable.css/wp-content/plugins/simple-follow-buttons/css/colorpicker.css/wp-content/plugins/simple-follow-buttons/css/switch.css/wp-content/plugins/simple-follow-buttons/css/admin-theme.css/wp-content/plugins/simple-follow-buttons/css/style.css/wp-content/plugins/simple-follow-buttons/js/bootstrap.js/wp-content/plugins/simple-follow-buttons/js/colorpicker.js/wp-content/plugins/simple-follow-buttons/js/switch.js+1 more//maxcdn.bootstrapcdn.com/font-awesome/4.3.0/css/font-awesome.min.cssHTML / DOM Fingerprints
sfb-containersfb_image_setsfb_sizesfb_pagessfb_postssfb_cats_archssfb_homepage+5 moresfb_settings