Social Engine Security & Risk Analysis

wordpress.org/plugins/social-engine

Schedule posts without subscription fees. Self-hosted, AI-powered, with full MCP support for intelligent automation.

600 active installs v0.8.7 PHP 7.4+ WP 6.0+ Updated Mar 10, 2026
facebookmediaschedulingsocialtwitter
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Engine Safe to Use in 2026?

Generally Safe

Score 100/100

Social Engine has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 25d ago
Risk Assessment

The "social-engine" plugin v0.8.7 demonstrates a strong security posture based on the provided static analysis. The complete absence of identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) and the fact that none of them are unprotected is a significant strength. The code also shows excellent practices regarding SQL queries, with 86% using prepared statements, and a very high rate of proper output escaping (94%), minimizing risks of XSS vulnerabilities. The plugin also implements a healthy number of capability checks, further bolstering its defenses.

However, the analysis does highlight a concerning lack of nonce checks (0), which is a critical security mechanism in WordPress to prevent CSRF attacks, especially on actions that modify data. While there are no direct indicators of critical taint flows or raw SQL queries without prepared statements, the absence of nonce checks leaves a significant blind spot. The vulnerability history is clean, with no recorded CVEs, which is positive, but this should not be a sole indicator of current security. The plugin's strengths lie in its limited attack surface and good output sanitization, but the missing nonce checks present a notable weakness that requires attention.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

Social Engine Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Social Engine Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
19 prepared
Unescaped Output
3
48 escaped
Nonce Checks
0
Capability Checks
14
File Operations
10
External Requests
4
Bundled Libraries
0

SQL Query Safety

86% prepared22 total queries

Output Escaping

94% escaped51 total outputs
Attack Surface

Social Engine Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 40
actionadmin_menuclasses\admin.php:9
actionadmin_enqueue_scriptsclasses\admin.php:21
actionrest_api_initclasses\api.php:11
filtersclegn_allow_public_apiclasses\api.php:20
actionplugins_loadedclasses\core.php:43
actioninitclasses\core.php:44
actiontransition_post_statusclasses\core.php:45
actionwp_after_insert_postclasses\core.php:46
filterpost_row_actionsclasses\core.php:47
actionadmin_noticesclasses\init.php:8
actioninitclasses\mcp.php:13
filtermwai_mcp_toolsclasses\mcp.php:22
filtermwai_mcp_callbackclasses\mcp.php:25
actionrest_api_initclasses\rest.php:15
actionplugins_loadedclasses\services\facebook.php:9
filtersclegn_modulesclasses\services\facebook.php:15
filtersclegn_accountsclasses\services\facebook.php:25
actionplugins_loadedclasses\services\instagram.php:8
filtersclegn_modulesclasses\services\instagram.php:12
actionplugins_loadedclasses\services\mastodon.php:7
filtersclegn_modulesclasses\services\mastodon.php:12
filtersclegn_accountsclasses\services\mastodon.php:22
actionplugins_loadedclasses\services\twitter.php:10
filtersclegn_modulesclasses\services\twitter.php:17
filtersclegn_accountsclasses\services\twitter.php:27
actionadmin_menuclasses\ui.php:8
actionadmin_bar_menuclasses\ui.php:9
actionadmin_noticescommon\admin.php:72
filterplugin_row_metacommon\admin.php:77
filteredd_sl_api_request_verify_sslcommon\admin.php:78
actioninitcommon\admin.php:96
actionadmin_menucommon\admin.php:153
filteradmin_footer_textcommon\admin.php:158
actionadmin_footercommon\admin.php:218
actionadmin_headcommon\admin.php:456
actionadmin_noticescommon\news.php:43
filtersafe_style_csscommon\news.php:44
actionadmin_noticescommon\ratings.php:33
filtersafe_style_csscommon\ratings.php:34
actionrest_api_initcommon\rest.php:14
Maintenance & Trust

Social Engine Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 10, 2026
PHP min version7.4
Downloads43K

Community Trust

Rating96/100
Number of ratings30
Active installs600
Developer Profile

Social Engine Developer Profile

Jordy Meow

27 plugins · 371K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
372 days
View full developer profile
Detection Fingerprints

How We Detect Social Engine

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-engine/app/index.js/wp-content/plugins/social-engine/app/vendor.js
Script Paths
/wp-content/plugins/social-engine/app/vendor.js/wp-content/plugins/social-engine/app/index.js
Version Parameters
social-engine/app/index.js?ver=social-engine/app/vendor.js?ver=

HTML / DOM Fingerprints

Data Attributes
id="sclegn-admin-settings"
JS Globals
sclegn_social_engine
REST Endpoints
/social-engine/api/v1/post/social-engine/api/v1/accounts/social-engine/api/v1/account
FAQ

Frequently Asked Questions about Social Engine