
Social Bookmarks Security & Risk Analysis
wordpress.org/plugins/social-bookmarksIt adds a list of XHTML graphic links at the end of your posts/pages that allow your visitors to easily submit them to bookmarking social sites.
Is Social Bookmarks Safe to Use in 2026?
Generally Safe
Score 85/100Social Bookmarks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "social-bookmarks" plugin version 4.1.6 exhibits a mixed security posture. On the positive side, the static analysis reveals a zero attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, with no entry points identified as unprotected. This indicates a good design practice in limiting direct interaction vectors. Furthermore, the absence of known CVEs and historical vulnerabilities suggests a relatively stable and well-maintained codebase in terms of discovered exploits.
However, significant concerns arise from the code analysis. The plugin performs all its SQL queries without using prepared statements, presenting a high risk of SQL injection vulnerabilities. Additionally, a substantial portion of its output is not properly escaped, leading to potential Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce and capability checks on any entry points, although the entry points themselves are zero, still points to a general disregard for input validation and authorization mechanisms. The file operation usage also warrants attention without further context. The taint analysis yielding zero flows is positive but might be limited by the analysis depth given the other identified code weaknesses.
In conclusion, while the plugin benefits from a lack of known vulnerabilities and a minimal attack surface, the raw SQL queries and unescaped output represent critical security weaknesses that could be exploited. The absence of security checks like nonces and capability checks is also a concern that needs addressing. The plugin is recommended for immediate review and remediation of the identified SQL and XSS risks.
Key Concerns
- All SQL queries use raw SQL, no prepared statements
- 0% of outputs are properly escaped
- 0 Nonce checks
- 0 Capability checks
Social Bookmarks Security Vulnerabilities
Social Bookmarks Code Analysis
SQL Query Safety
Output Escaping
Social Bookmarks Attack Surface
WordPress Hooks 6
Maintenance & Trust
Social Bookmarks Maintenance & Trust
Maintenance Signals
Community Trust
Social Bookmarks Alternatives
The Social Links
the-social-links
The Social Links plugin adds a widget and shortcode to your WordPress website allowing you to display icons linking to your social profiles.
Social Media Engine
social-media-engine
Social follow links shortcode. Built on FontAwesome icons. 30 social networks supported: 500px, behance, bitbucket, delicious, deviantart, digg, drib …
Social Bookmarking JP
social-bookmarking-jp
Embedding Japanese major social bookmark services hyper links and icons
Powerkit – Supercharge your WordPress Site
powerkit
Essential components for every WordPress site: share buttons, social links, social media integrations, galleries, lazyload, custom widgets, and more.
RaraTheme Companion
raratheme-companion
23 extremely useful custom widgets to create an engaging website.
Social Bookmarks Developer Profile
2 plugins · 150 total installs
How We Detect Social Bookmarks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-bookmarks/social_bookmarks.css/wp-content/plugins/social-bookmarks/social_bookmarks.js/wp-content/plugins/social-bookmarks/social_bookmarks.jssocial-bookmarks/social_bookmarks.css?ver=social-bookmarks/social_bookmarks.js?ver=HTML / DOM Fingerprints
sb_social_bookmark_list<!-- Social Bookmarks by Apostolos Dountsis -->data-sbb_tooltip_textdata-sbb_targetsbb_ajax_dropdown_enabledsbb_ajax_dropdown_hidesbb_ajax_dropdown_speed[social_bookmarks]