
Social Media Auto Publish Security & Risk Analysis
wordpress.org/plugins/social-media-auto-publishPublish posts automatically to social media networks like Facebook, Twitter, Instagram, Tumblr, LinkedIn, Threads and Telegram.
Is Social Media Auto Publish Safe to Use in 2026?
Generally Safe
Score 99/100Social Media Auto Publish has a strong security track record. Known vulnerabilities have been patched promptly.
The "social-media-auto-publish" plugin version 3.6.8 exhibits a mixed security posture. While it demonstrates several good security practices, such as a significant number of nonce and capability checks, and a good proportion of SQL queries using prepared statements, there are notable areas of concern. The presence of the `unserialize` function, a known dangerous function, without explicit context on its usage or sanitization is a significant red flag. Furthermore, the taint analysis indicates flows with unsanitized paths, although fortunately classified as not critical or high severity.
The plugin's vulnerability history shows one medium severity CVE in the past, indicating that past vulnerabilities have been addressed. However, the common vulnerability type being Cross-site Scripting is a persistent concern in web applications. The overall attack surface is primarily through AJAX handlers, and while all are reported to have auth checks, the sheer number could present a larger potential for misconfigurations or future vulnerabilities if not meticulously maintained. The output escaping is also a concern, with only 38% properly escaped, increasing the risk of XSS attacks. The bundled Guzzle library, while not inherently insecure, could pose a risk if it's outdated and has known vulnerabilities.
In conclusion, the plugin has strengths in its authentication and authorization checks for its entry points, and a good track record of patching vulnerabilities. However, the use of `unserialize`, a significant portion of improperly escaped output, and unsanitized paths in taint flows represent genuine risks that require careful attention and potential mitigation. The plugin's security can be considered moderate, with specific areas needing improvement to reach a more robust state.
Key Concerns
- Dangerous function 'unserialize' used
- Only 38% of outputs properly escaped
- Flows with unsanitized paths found
- Bundled library Guzzle
- Past medium severity CVE exists
Social Media Auto Publish Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Social Media Auto Publish <= 3.6.5 - Reflected Cross-Site Scripting via PostMessage
Social Media Auto Publish Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Social Media Auto Publish Attack Surface
AJAX Handlers 11
WordPress Hooks 16
Scheduled Events 1
Maintenance & Trust
Social Media Auto Publish Maintenance & Trust
Maintenance Signals
Community Trust
Social Media Auto Publish Alternatives
WP Twitter Auto Publish
twitter-auto-publish
Publish posts automatically to Twitter.
WP to LinkedIn Auto Publish
linkedin-auto-publish
Publish posts automatically to LinkedIn.
Social Web Suite – Social Media Auto Post, Social Media Auto Publish
social-web-suite
Social media auto post, social media auto publish, schedule, share, and promote your new, and re-share your old posts to Instagram, X(Twitter), Facebo …
Auto Post for Twitter
auto-post-for-twitter
Publish posts automatically to Twitter.
Oktopost Future Posts
oktopost-future-posts
Easily include link attachments, in your social content, to blog posts that have not yet been published.
Social Media Auto Publish Developer Profile
15 plugins · 142K total installs
How We Detect Social Media Auto Publish
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-media-auto-publish/css/font-awesome.min.css/wp-content/plugins/social-media-auto-publish/css/style.css/wp-content/plugins/social-media-auto-publish/js/notice.js/wp-content/plugins/social-media-auto-publish/js/notice.jssocial-media-auto-publish/css/font-awesome.min.css?ver=social-media-auto-publish/css/style.css?ver=HTML / DOM Fingerprints
xyz_smap_credit_linkxyz_smap_varXYZ_SMAP_CONSTxyz_script_smap_var