Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more Security & Risk Analysis

wordpress.org/plugins/social-boost

Run viral giveaways, contests, competitions, sweepstakes, purchase for chance to win, instant wins, refer-a-friend, and boost subscribers, followers, …

100 active installs v3.6.0 PHP + WP 3.0.1+ Updated Jan 12, 2026
black-fridaychristmascontestgiveawayspromotion
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more Safe to Use in 2026?

Generally Safe

Score 100/100

Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "social-boost" v3.6.0 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and having a clean vulnerability history with no known CVEs. The code also shows a decent rate of output escaping, with 83% of outputs properly handled. However, significant concerns arise from its attack surface. A substantial number of AJAX handlers and REST API routes lack proper authentication and permission checks, creating an open door for unauthorized actions. The taint analysis further highlights this risk, revealing two high-severity flows with unsanitized paths, indicating potential for command injection or similar critical vulnerabilities if these flows are triggered by attacker-controlled input.

While the absence of past vulnerabilities might suggest a generally secure development process, the current code analysis reveals critical weaknesses that need immediate attention. The high number of unprotected entry points, coupled with high-severity taint flows, creates a significant risk of exploitation. The plugin's reliance on external HTTP requests, while not inherently a vulnerability, could become a vector if the endpoints it communicates with are compromised or if the data sent/received is not properly validated and escaped before use. In conclusion, "social-boost" v3.6.0 has strengths in its SQL handling and vulnerability history, but its extensive unprotected attack surface and high-severity taint flows represent a serious security risk that overshadows these positive aspects.

Key Concerns

  • AJAX handlers without auth checks
  • REST API routes without permission callbacks
  • High severity taint flows
  • Unsanitized paths in taint flows
  • Nonce checks missing (only 1 found)
  • Capability checks missing (only 3 found)
  • Output escaping rate below 90%
Vulnerabilities
None known

Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
10 prepared
Unescaped Output
19
91 escaped
Nonce Checks
1
Capability Checks
3
File Operations
2
External Requests
10
Bundled Libraries
0

SQL Query Safety

100% prepared10 total queries

Output Escaping

83% escaped110 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

6 flows5 with unsanitized paths
set_settings (includes\socialboost-api.php:459)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
15 unprotected

Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more Attack Surface

Entry Points21
Unprotected15

AJAX Handlers 6

authwp_ajax_create_grvlsw_accountsocialboost.php:156
authwp_ajax_check_grvlsw_settingssocialboost.php:157
authwp_ajax_code_grvlsw_settingssocialboost.php:158
authwp_ajax_sendcode_grvlsw_settingssocialboost.php:159
authwp_ajax_check_grvlsw_loginsocialboost.php:160
authwp_ajax_check_sb_autologinsocialboost.php:161

REST API Routes 14

GET/wp-json/socialboost/v1/getPageincludes\socialboost-api.php:10
GET/wp-json/socialboost/v1/addPageincludes\socialboost-api.php:18
GET/wp-json/socialboost/v1/editPageincludes\socialboost-api.php:26
GET/wp-json/socialboost/v1/deletePageincludes\socialboost-api.php:34
POST/wp-json/socialboost/v1/getversionincludes\socialboost-api.php:43
GET/wp-json/socialboost/v1/resetInstallationincludes\socialboost-api.php:49
POST/wp-json/socialboost/v1/getorderdetailsincludes\socialboost-api.php:57
GET/wp-json/socialboost/v1/setSettingsincludes\socialboost-api.php:63
POST/wp-json/socialboost/v1/createcustomerincludes\socialboost-api.php:72
POST/wp-json/socialboost/v1/verifyUserincludes\socialboost-api.php:79
POST/wp-json/socialboost/v1/getproductcategoriesincludes\socialboost-api.php:86
GET/wp-json/socialboost/v1/createCouponSBincludes\socialboost-api.php:93
GET/wp-json/socialboost/v1/verifyCouponCodeincludes\socialboost-api.php:102
GET/wp-json/socialboost/v1/deleteCouponCodeincludes\socialboost-api.php:111

Shortcodes 1

[sb-campaign] socialboost.php:1893
WordPress Hooks 15
actionadmin_initsocialboost.php:52
actionadmin_menusocialboost.php:53
actionwp_footersocialboost.php:54
actionadmin_enqueue_scriptssocialboost.php:55
actionsave_postsocialboost.php:56
actiondelete_postsocialboost.php:57
actionplugins_loadedsocialboost.php:59
actionrest_api_initsocialboost.php:62
actionupgrader_process_completesocialboost.php:64
actioncomment_postsocialboost.php:916
actionwpsocialboost.php:917
actionwoocommerce_checkout_order_processedsocialboost.php:920
actionwoocommerce_order_status_changedsocialboost.php:921
actionwoocommerce_order_refundedsocialboost.php:922
actionbefore_delete_postsocialboost.php:923
Maintenance & Trust

Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 12, 2026
PHP min version
Downloads40K

Community Trust

Rating100/100
Number of ratings25
Active installs100
Developer Profile

Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more Developer Profile

Apps Mav

4 plugins · 1K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
3 days
View full developer profile
Detection Fingerprints

How We Detect Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-boost/assets/css/sb-admin.css/wp-content/plugins/social-boost/assets/js/sb-admin.js/wp-content/plugins/social-boost/includes/compat/polyfills.php/wp-content/plugins/social-boost/assets/css/socialboost.css/wp-content/plugins/social-boost/assets/js/socialboost.js
Script Paths
/wp-content/plugins/social-boost/assets/js/sb-admin.js/wp-content/plugins/social-boost/assets/js/socialboost.js
Version Parameters
social-boost/assets/css/sb-admin.css?ver=social-boost/assets/js/sb-admin.js?ver=social-boost/includes/compat/polyfills.php?ver=social-boost/assets/css/socialboost.css?ver=social-boost/assets/js/socialboost.js?ver=

HTML / DOM Fingerprints

CSS Classes
socialboost-widgetsb-widgetSBEmbedContainersb_iframe_widget
Data Attributes
data-sbclass
JS Globals
SBmavtokenamsb_preg_matchamsb_strlen
REST Endpoints
/wp-json/social-boost/v1/settings
Shortcode Output
<div class="SBEmbedContainer"><iframe data-sbclass="sb_iframe_widget" class="sb_iframe_widget" width="100%" height="700px" src="https://social.appsmav.com/promo/<a class="socialboost-widget sb-widget" href="
FAQ

Frequently Asked Questions about Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more