Simple Social Images Security & Risk Analysis

wordpress.org/plugins/simple-social-images

Automatically generate beautiful and branded social sharing images for posts.

0 active installs v1.0 PHP 8.0+ WP 6.0+ Updated Sep 21, 2022
open-graphsocial-imagessocial-mediasocial-sharingtwitter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Social Images Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Social Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "simple-social-images" plugin v1.0 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and properly escaping the vast majority of output, several critical areas raise concern. The plugin has one unprotected REST API route, representing a significant attack surface for unauthorized access or manipulation. Additionally, the taint analysis revealed a flow with unsanitized paths, indicating a potential vulnerability for path traversal or file inclusion attacks, though it was not categorized as critical. The absence of any known historical vulnerabilities is a positive sign, suggesting the developers may have a history of producing secure code or that the plugin has not been widely targeted. However, the presence of an unprotected REST API and the unsanitized path flow are immediate and actionable risks that need to be addressed.

Key Concerns

  • Unprotected REST API route
  • Flow with unsanitized paths
  • Zero capability checks
Vulnerabilities
None known

Simple Social Images Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Simple Social Images Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
224 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

98% escaped229 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<generate-html> (endpoints\generate-html.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Simple Social Images Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/ssi/v1/getimage/inc\endpoints.php:83
WordPress Hooks 53
actionadmin_menuinc\admin-menu.php:19
actioninitinc\endpoints.php:16
filterrequestinc\endpoints.php:43
filtertemplate_includeinc\endpoints.php:75
actionrest_api_initinc\endpoints.php:95
actionadmin_enqueue_scriptsinc\enqueue.php:87
actionhd_ssi_before_settings_form_outputinc\filter.php:25
actionhd_ssi_after_settings_form_outputinc\filter.php:52
filterhd_ssi_template_output_post_authorinc\filter.php:86
filterhd_ssi_template_output_post_dateinc\filter.php:119
filterhd_ssi_template_output_author_avatar_urlinc\filter.php:151
actionhd_ssi_generate_html_headinc\filter.php:166
actionhd_ssi_generate_html_headinc\filter.php:180
actionhd_ssi_generate_html_headinc\filter.php:205
actionadmin_initinc\filter.php:257
actionadmin_initinc\filter.php:314
actionafter_setup_themeinc\functions.php:26
actionwp_headinc\functions.php:298
actionadd_meta_boxesinc\meta-box.php:28
filterhd_ssi_wpjm_render_og_image_tagsinc\plugins\all-in-one-seo.php:25
filteraioseo_facebook_tagsinc\plugins\all-in-one-seo.php:33
filterhd_ssi_wpjm_render_twitter_image_tagsinc\plugins\all-in-one-seo.php:54
filteraioseo_twitter_tagsinc\plugins\all-in-one-seo.php:62
filterhd_ssi_render_og_image_tagsinc\plugins\rank-math-seo.php:53
filterrank_math/opengraph/facebook/og_imageinc\plugins\rank-math-seo.php:65
filterrank_math/opengraph/facebook/og_image_secure_urlinc\plugins\rank-math-seo.php:66
filterhd_ssi_render_twitter_image_tagsinc\plugins\rank-math-seo.php:79
filterrank_math/opengraph/twitter/imageinc\plugins\rank-math-seo.php:89
filterhd_ssi_render_og_image_tagsinc\plugins\yoast-seo.php:62
filterhd_ssi_render_twitter_image_tagsinc\plugins\yoast-seo.php:75
filterwpseo_frontend_presentersinc\plugins\yoast-seo.php:95
actionadmin_initinc\settings.php:72
filterhd_ssi_settingsinc\settings.php:663
actionhd_ssi_setting_type_textinc\settings.php:682
actionhd_ssi_setting_type_numberinc\settings.php:721
actionhd_ssi_setting_type_textareainc\settings.php:740
actionhd_ssi_setting_type_hiddeninc\settings.php:759
actionhd_ssi_setting_type_selectinc\settings.php:799
actionhd_ssi_setting_type_checkboxinc\settings.php:821
actionhd_ssi_setting_type_checkboxesinc\settings.php:863
actionhd_ssi_setting_type_color_pickerinc\settings.php:882
actionhd_ssi_setting_type_imageinc\settings.php:931
actionhd_ssi_setting_type_galleryinc\settings.php:1020
actionhd_ssi_setting_type_rangeinc\settings.php:1059
actionhd_ssi_setting_type_sectioninc\settings.php:1081
actionhd_ssi_setting_type_licenseinc\settings.php:1134
actionhd_ssi_after_settinginc\settings.php:1153
actionhd_ssi_before_settings_wrapperinc\settings.php:1188
actionhd_ssi_after_settings_wrapperinc\settings.php:1223
actionhd_si_after_setting_labelinc\settings.php:1251
actionplugins_loadedsimple-social-images.php:30
actionadmin_initsimple-social-images.php:94
actioninitsimple-social-images.php:114
Maintenance & Trust

Simple Social Images Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 21, 2022
PHP min version8.0
Downloads804

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Simple Social Images Developer Profile

Highrise Digital

3 plugins · 200 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Social Images

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-social-images/assets/js/hd-ssi-editor.js/wp-content/plugins/simple-social-images/assets/css/hd-ssi-admin.css/wp-content/plugins/simple-social-images/assets/css/hd-ssi-generate.css/wp-content/plugins/simple-social-images/assets/js/hd-ssi-settings.js
Script Paths
hd-ssi-editor.jshd-ssi-settings.js
Version Parameters
hd-ssi-editor.js?ver=hd-ssi-admin.css?ver=hd-ssi-generate.css?ver=hd-ssi-settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
ssi-template
Data Attributes
data-ssi-background-colordata-ssi-text-colordata-ssi-button-colordata-ssi-button-text-color
JS Globals
wpApiSettings
REST Endpoints
/wp-json/hd_ssi/v1/get_post_data/wp-json/hd_ssi/v1/get_settings
FAQ

Frequently Asked Questions about Simple Social Images