
Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more Security & Risk Analysis
wordpress.org/plugins/social-boostRun viral giveaways, contests, competitions, sweepstakes, purchase for chance to win, instant wins, refer-a-friend, and boost subscribers, followers, …
Is Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more Safe to Use in 2026?
Generally Safe
Score 100/100Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "social-boost" v3.6.0 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and having a clean vulnerability history with no known CVEs. The code also shows a decent rate of output escaping, with 83% of outputs properly handled. However, significant concerns arise from its attack surface. A substantial number of AJAX handlers and REST API routes lack proper authentication and permission checks, creating an open door for unauthorized actions. The taint analysis further highlights this risk, revealing two high-severity flows with unsanitized paths, indicating potential for command injection or similar critical vulnerabilities if these flows are triggered by attacker-controlled input.
While the absence of past vulnerabilities might suggest a generally secure development process, the current code analysis reveals critical weaknesses that need immediate attention. The high number of unprotected entry points, coupled with high-severity taint flows, creates a significant risk of exploitation. The plugin's reliance on external HTTP requests, while not inherently a vulnerability, could become a vector if the endpoints it communicates with are compromised or if the data sent/received is not properly validated and escaped before use. In conclusion, "social-boost" v3.6.0 has strengths in its SQL handling and vulnerability history, but its extensive unprotected attack surface and high-severity taint flows represent a serious security risk that overshadows these positive aspects.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- High severity taint flows
- Unsanitized paths in taint flows
- Nonce checks missing (only 1 found)
- Capability checks missing (only 3 found)
- Output escaping rate below 90%
Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more Security Vulnerabilities
Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more Attack Surface
AJAX Handlers 6
REST API Routes 14
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more Maintenance & Trust
Maintenance Signals
Community Trust
Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more Alternatives
Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program
gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce
Loyalty + Referral + Rewards + Birthdays and Anniversaries + Giveaways + Contests + Competitions + Sweepstakes. Selling on ETSY? Reward points for yo …
Gratisfaction- Contests Giveaways Referral Loyalty Rewards and Birthdays Program
gratisfaction-social-contests-referral-loyalty-rewards-program-by-appsmav
All-in-One Loyalty + Giveaways + Contests + Competitions + Referral + Birthdays + Anniversaries App. No Coding. Easy DIY Setup.
Woobox
woobox
Easily embed your Woobox promotions in WordPress using a simple shortcode.
Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more
scratch-win-giveaways-for-website-facebook
Display a Scratch Card on your website to offer visitors a chance to win prizes. A fun incentive to boost conversions!
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers
rafflepress
The best WordPress giveaway plugin. Grow your email list, website traffic, and social media followers with viral contests, giveaways, and sweepstakes.
Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more Developer Profile
4 plugins · 1K total installs
How We Detect Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-boost/assets/css/sb-admin.css/wp-content/plugins/social-boost/assets/js/sb-admin.js/wp-content/plugins/social-boost/includes/compat/polyfills.php/wp-content/plugins/social-boost/assets/css/socialboost.css/wp-content/plugins/social-boost/assets/js/socialboost.js/wp-content/plugins/social-boost/assets/js/sb-admin.js/wp-content/plugins/social-boost/assets/js/socialboost.jssocial-boost/assets/css/sb-admin.css?ver=social-boost/assets/js/sb-admin.js?ver=social-boost/includes/compat/polyfills.php?ver=social-boost/assets/css/socialboost.css?ver=social-boost/assets/js/socialboost.js?ver=HTML / DOM Fingerprints
socialboost-widgetsb-widgetSBEmbedContainersb_iframe_widgetdata-sbclassSBmavtokenamsb_preg_matchamsb_strlen/wp-json/social-boost/v1/settings<div class="SBEmbedContainer"><iframe data-sbclass="sb_iframe_widget" class="sb_iframe_widget" width="100%" height="700px" src="https://social.appsmav.com/promo/<a class="socialboost-widget sb-widget" href="