
Social Media Engine Security & Risk Analysis
wordpress.org/plugins/social-media-engineSocial follow links shortcode. Built on FontAwesome icons. 30 social networks supported: 500px, behance, bitbucket, delicious, deviantart, digg, drib …
Is Social Media Engine Safe to Use in 2026?
Use With Caution
Score 64/100Social Media Engine has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "social-media-engine" plugin v1.0.2 exhibits a mixed security posture. While the static analysis reveals no directly exploitable attack vectors through AJAX or REST API endpoints, and all SQL queries use prepared statements, significant concerns arise from the complete lack of output escaping. This indicates a high probability of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied input could be injected and executed within the browser. The absence of nonce checks and capability checks on the single identified shortcode entry point further exacerbates this risk, as it implies that actions triggered by the shortcode might not be properly authorized or protected against CSRF attacks.
The vulnerability history shows a known medium severity vulnerability of the Cross-Site Scripting type, which aligns with the concerns raised by the static analysis regarding output escaping. The fact that this vulnerability is currently unpatched is a critical red flag, indicating an immediate risk to users of this plugin. The consistent pattern of XSS vulnerabilities suggests a recurring lack of secure coding practices in handling user input and rendering output within the plugin.
In conclusion, while the plugin avoids some common pitfalls like raw SQL queries and a broad attack surface, the critical issues of unescaped output and an unpatched XSS vulnerability present a substantial security risk. The absence of essential security checks like nonces and capability checks on its entry point further weakens its security posture. Users should exercise extreme caution and consider updating to a patched version if available, or otherwise avoid using this plugin until these critical issues are addressed.
Key Concerns
- Unpatched medium CVE (XSS)
- 0% proper output escaping
- 0 Nonce checks
- 0 Capability checks
Social Media Engine Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Social Media Engine <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Social Media Engine Code Analysis
Output Escaping
Social Media Engine Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Social Media Engine Maintenance & Trust
Maintenance Signals
Community Trust
Social Media Engine Alternatives
The Social Links
the-social-links
The Social Links plugin adds a widget and shortcode to your WordPress website allowing you to display icons linking to your social profiles.
WPSocialite
wpsocialite
Long page loads aren't fun for anyone. Use WPSocialite to take control of heavy social sharing links and load them how you want!
Simple Social Icons
simple-social-icons
This plugin provides two ways to display social icons: a traditional widget (available on all WordPress versions) and block variations for the core So …
Lightweight Social Icons
lightweight-social-icons
Looking to add simple social icons to your widget areas? Choose the size and color of your icons, and then choose from 47 different social profiles.
Powerkit – Supercharge your WordPress Site
powerkit
Essential components for every WordPress site: share buttons, social links, social media integrations, galleries, lazyload, custom widgets, and more.
Social Media Engine Developer Profile
1 plugin · 40 total installs
How We Detect Social Media Engine
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-media-engine/css/style.css/wp-content/plugins/social-media-engine/font-awesome/css/font-awesome.cssHTML / DOM Fingerprints
sme-social-follow<div class="sme-social-follow<li><a href=<i class="fa fa-500px"></i><i class="fa fa-behance"></i>