TechGasp Social Master Security & Risk Analysis

wordpress.org/plugins/social-master

TechGasp Social Master is a light weight and shiny clean code wordpress plugin WIDGET that you need to boost your wordpress social engagement.

40 active installs v5.1.4 PHP + WP 3.5+ Updated Mar 11, 2021
facebookgoogleinstagrampinteresttwitter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TechGasp Social Master Safe to Use in 2026?

Generally Safe

Score 85/100

TechGasp Social Master has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of the 'social-master' plugin v5.1.4 reveals a mixed security posture. On the positive side, the plugin demonstrates good practices by avoiding common attack vectors like AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points. Furthermore, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which significantly reduces the potential for certain types of attacks. However, a notable concern is the output escaping, with only 44% of outputs being properly escaped. This suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data might be rendered directly in the browser without sufficient sanitization.

The taint analysis shows 2 flows with unsanitized paths, which, while not flagged as critical or high severity, still represent potential security weaknesses that could be exploited. The presence of a single nonce check indicates some level of attention to security, but the complete absence of capability checks is a significant omission. This means that actions within the plugin might not be properly authorized, potentially allowing unprivileged users to perform restricted operations.

The vulnerability history for 'social-master' is clean, with no recorded CVEs, unpatched vulnerabilities, or common vulnerability types. This lack of historical issues is encouraging, but it does not negate the risks identified in the static and taint analysis. The plugin's strengths lie in its limited attack surface and secure handling of SQL queries, but the weak output escaping and lack of capability checks present tangible risks that require attention.

Key Concerns

  • Low output escaping percentage
  • Taint flows with unsanitized paths
  • No capability checks
Vulnerabilities
None known

TechGasp Social Master Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TechGasp Social Master Release Timeline

v5.1.4Current
v5.1.2
v5.1.1
v5.1.0
v5.0.15
v5.0.12
v5.0.11
v5.0.10
v5.0.9
v5.0.8
v5.0.6
v5.0.5
v5.0.4
v5.0
v4.4.5
v4.4.4
v4.4.3
v4.4.2.7
v4.4.2.6
v4.4.2.5
Code Analysis
Analyzed Mar 16, 2026

TechGasp Social Master Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
106
84 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

44% escaped190 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
display (includes\social-master-admin-settings-wide-table-options.php:10)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

TechGasp Social Master Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menuincludes\social-master-admin-addons.php:39
actionadmin_menuincludes\social-master-admin-addons.php:42
actionadmin_menuincludes\social-master-admin-settings-wide.php:51
actionadmin_menuincludes\social-master-admin-settings-wide.php:54
actionnetwork_admin_menuincludes\social-master-admin.php:10
actionadmin_menuincludes\social-master-admin.php:11
actionadmin_menuincludes\social-master-admin.php:14
actionwidgets_initincludes\social-master-widget-basic.php:3
filterthe_contentsocial-master.php:52
filterplugin_action_linkssocial-master.php:53
Maintenance & Trust

TechGasp Social Master Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 11, 2021
PHP min version
Downloads28K

Community Trust

Rating82/100
Number of ratings13
Active installs40
Developer Profile

TechGasp Social Master Developer Profile

TechGasp

20 plugins · 3K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TechGasp Social Master

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-master/includes/social-master-admin.php/wp-content/plugins/social-master/includes/social-master-admin-settings-wide.php/wp-content/plugins/social-master/includes/social-master-admin-addons.php/wp-content/plugins/social-master/includes/social-master-widget-basic.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about TechGasp Social Master