Sociable-Italia Security & Risk Analysis

wordpress.org/plugins/sociable-italia

Automatically add links on your posts, pages and RSS feed to your favorite social bookmarking sites.

10 active installs v3.0.8 PHP + WP 2.6+ Updated Feb 11, 2010
bookmarkbookmarkingbookmarkssocialsocial-bookmarking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sociable-Italia Safe to Use in 2026?

Generally Safe

Score 85/100

Sociable-Italia has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The "sociable-italia" v3.0.8 plugin presents a mixed security posture. On the positive side, the plugin has a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, no entry points that lack authorization checks. This suggests a deliberate effort to limit potential attack vectors. The taint analysis also yielded no critical or high severity flows, indicating that internal data handling might be reasonably secure.

However, several concerning code signals raise red flags. The presence of `create_function` is a known security risk that can lead to arbitrary code execution if user input is not meticulously sanitized before being passed to it. Furthermore, the plugin performs SQL queries that are not prepared, which is a significant vulnerability risk for SQL injection. The complete lack of output escaping for any of the identified outputs is also deeply concerning, making it highly susceptible to cross-site scripting (XSS) attacks.

The plugin's vulnerability history is clean, with no recorded CVEs. While this is a positive indicator, it does not negate the clear risks identified in the static analysis. The absence of past vulnerabilities might be due to the plugin's limited functionality or usage, rather than robust security practices. Overall, the minimal attack surface is a strength, but the critical flaws in code execution, SQL handling, and output sanitization represent substantial security weaknesses that require immediate attention.

Key Concerns

  • Dangerous function create_function used
  • SQL queries not using prepared statements
  • No output escaping
Vulnerabilities
None known

Sociable-Italia Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Sociable-Italia Code Analysis

Dangerous Functions
1
Raw SQL Queries
1
0 prepared
Unescaped Output
25
0 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action( 'plugins_loaded', create_function( '', 'global $YoastPosts; $YoastPosts = new YoastPostsyoast-posts.php:58

SQL Query Safety

0% prepared1 total queries

Output Escaping

0% escaped25 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
sociable_submenu (sociable.php:1176)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sociable-Italia Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
filterinitsociable.php:50
filterthe_contentsociable.php:961
filterthe_excerptsociable.php:962
actionadmin_menusociable.php:1062
actionadmin_print_scriptssociable.php:1078
actionadmin_print_stylessociable.php:1089
actionwp_print_scriptssociable.php:1111
actionwp_print_stylessociable.php:1126
actionadmin_menusociable.php:1157
actionwp_insert_postsociable.php:1171
filterozh_adminmenu_iconsociable.php:1471
filterplugin_action_linkssociable.php:1488
actionwp_dashboard_setupsociable.php:1543
actionwp_dashboard_setupyoast-posts.php:17
filterwp_dashboard_widgetsyoast-posts.php:18
actionplugins_loadedyoast-posts.php:58
Maintenance & Trust

Sociable-Italia Maintenance & Trust

Maintenance Signals

WordPress version tested2.9.2
Last updatedFeb 11, 2010
PHP min version
Downloads12K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Sociable-Italia Developer Profile

Andrea Pernici

6 plugins · 1K total installs

81
trust score
Avg Security Score
82/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sociable-Italia

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sociable-italia/sociable-italia.css/wp-content/plugins/sociable-italia/sociable-italia.js/wp-content/plugins/sociable-italia/admin/sociable-italia-admin.css/wp-content/plugins/sociable-italia/admin/sociable-italia-admin.js
Script Paths
/wp-content/plugins/sociable-italia/sociable-italia.js/wp-content/plugins/sociable-italia/admin/sociable-italia-admin.js
Version Parameters
sociable-italia/sociable-italia.css?ver=sociable-italia/sociable-italia.js?ver=sociable-italia/admin/sociable-italia-admin.css?ver=sociable-italia/admin/sociable-italia-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
sociable-italia-iconsociable-italia-social-wrapper
HTML Comments
<!-- Sociable-Italia social links -->
JS Globals
sociable_italia_ajax_urlsociable_italia_settings
FAQ

Frequently Asked Questions about Sociable-Italia