Social Header Meta Security & Risk Analysis

wordpress.org/plugins/social-header-meta

Setup meta tags in the header for Facebook and Twitter.

10 active installs v4.0 PHP + WP 3.0.1+ Updated Sep 24, 2013
facebook-sharemeta-tagssocialtwitter-cards
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Header Meta Safe to Use in 2026?

Generally Safe

Score 85/100

Social Header Meta has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

Based on the static analysis, the "social-header-meta" v4.0 plugin presents a generally good security posture with no identified critical vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code exhibits strong practices regarding SQL queries, exclusively using prepared statements, and no file operations or external HTTP requests were detected. The plugin also shows a clean vulnerability history with zero recorded CVEs, indicating a history of stable and secure development.

However, there are areas for improvement. The presence of unescaped output in 67% of the identified outputs, although not critical in this instance due to the limited attack surface, represents a potential risk for cross-site scripting (XSS) vulnerabilities if the plugin were to be extended or integrated with user-provided data in the future. Additionally, the lack of explicit capability checks and nonce checks on any potential entry points, while currently not exploitable due to the lack of entry points, signifies a gap in best practices that could become a liability with future code additions. Overall, the plugin is currently secure due to its minimal attack surface and lack of historical vulnerabilities, but it could benefit from implementing output escaping more consistently and considering capability checks for future development.

Key Concerns

  • Unescaped output present
  • Missing capability checks on entry points
  • Missing nonce checks on entry points
Vulnerabilities
None known

Social Header Meta Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Social Header Meta Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Social Header Meta Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped3 total outputs
Attack Surface

Social Header Meta Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_headsocial-header.php:51
actionadmin_menusocial-header.php:66
actionadmin_initsocial-header.php:67
Maintenance & Trust

Social Header Meta Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedSep 24, 2013
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Social Header Meta Developer Profile

landykos

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Social Header Meta

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Social Header Meta