
Social Media Badge Widget Security & Risk Analysis
wordpress.org/plugins/social-media-badge-widgetThis plugin creates a widget which easily displays the social badges from the leading social media websites in a clear an elegant way.
Is Social Media Badge Widget Safe to Use in 2026?
Generally Safe
Score 85/100Social Media Badge Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'social-media-badge-widget' plugin v2.7.0 exhibits a mixed security posture. On the positive side, there are no known CVEs, no raw SQL queries, and a good number of identified output operations are properly escaped. The plugin also correctly implements nonce and capability checks, indicating some awareness of WordPress security best practices. The absence of file operations and external HTTP requests further reduces potential attack vectors.
However, the presence of the `create_function` PHP construct is a significant concern. While not directly linked to a taint flow in this analysis, `create_function` is deprecated and can be a source of vulnerabilities, especially if user-supplied data is passed into it without proper sanitization. The low percentage of properly escaped outputs (23%) suggests that a substantial number of dynamic outputs might be vulnerable to cross-site scripting (XSS) attacks if they handle user-controlled data, even though no specific taint flows were identified in this static analysis. The lack of any identified entry points in the static analysis is unusual and could mean the scan was incomplete or that the plugin genuinely has no direct user-facing interactions that the tools could detect.
Given the clean vulnerability history and the absence of identified critical taint flows, the immediate risk appears to be moderate. The primary concerns stem from the use of `create_function` and the high proportion of unescaped output. A comprehensive security audit would be beneficial to confirm the absence of vulnerabilities related to these areas and to ensure the static analysis covered all plugin functionalities.
Key Concerns
- Use of deprecated and potentially dangerous function (create_function)
- Low percentage of properly escaped outputs
Social Media Badge Widget Security Vulnerabilities
Social Media Badge Widget Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Social Media Badge Widget Attack Surface
WordPress Hooks 8
Maintenance & Trust
Social Media Badge Widget Maintenance & Trust
Maintenance Signals
Community Trust
Social Media Badge Widget Alternatives
Social Icons Widget
social-icons-widget
A developer-friendly plugin that allows you to add a widget with links to various social media profiles.
Round Social Media Buttons
round-social-media-buttons
Provides a responsive social media widget that displays up to eight different social media websites.
Feeder Ninja: Create and add RSS & Social feeds to your website on-the-fly
feeder-ninja-feed
The best tool for adding RSS & Social media feeds to your Wordpress website. Powered by Common Ninja.
TweetRoll
tweetroll
TweetRoll displays your Twitter details and the avatars of some of your friends, together with the ability to monitise your Twitter stream.
Open Graph and Twitter Card Tags
wonderm00ns-simple-facebook-open-graph-tags
Improve social media sharing by inserting Facebook Open Graph, Twitter Card, and SEO Meta Tags on your WordPress website pages, posts, WooCommerce pro …
Social Media Badge Widget Developer Profile
1 plugin · 200 total installs
How We Detect Social Media Badge Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-media-badge-widget/css/jquery-ui-grey.min.css/wp-content/plugins/social-media-badge-widget/css/jquery-ui-black.min.css/wp-content/plugins/social-media-badge-widget/css/jquery-ui-blue.min.css/wp-content/plugins/social-media-badge-widget/css/jquery-ui-red.min.css/wp-content/plugins/social-media-badge-widget/css/jquery-ui-green.min.css/wp-content/plugins/social-media-badge-widget/css/jquery-ui-skeleton.min.css/wp-content/plugins/social-media-badge-widget/css/social-media-badge-widget-skeleton.min.css/wp-content/plugins/social-media-badge-widget/css/social-media-badge-widget.min.css+1 moresocial-media-badge-widget/js/social-media-badge-widget.min.jssocial-media-badge-widget/css/jquery-ui-grey.min.css?ver=social-media-badge-widget/css/jquery-ui-black.min.css?ver=social-media-badge-widget/css/jquery-ui-blue.min.css?ver=social-media-badge-widget/css/jquery-ui-red.min.css?ver=social-media-badge-widget/css/jquery-ui-green.min.css?ver=social-media-badge-widget/css/jquery-ui-skeleton.min.css?ver=social-media-badge-widget/css/social-media-badge-widget-skeleton.min.css?ver=social-media-badge-widget/css/social-media-badge-widget.min.css?ver=social-media-badge-widget/js/social-media-badge-widget.min.js?ver=HTML / DOM Fingerprints
smbwwebsite_information