Social Media Icons Widget Security & Risk Analysis

wordpress.org/plugins/social-media-icons

Developed at NCI.

1K active installs v1.2.7 PHP + WP 3.0+ Updated Nov 28, 2017
diggfacebookiconssocial-mediatwitter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Media Icons Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Social Media Icons Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "social-media-icons" plugin v1.2.7 exhibits a generally strong security posture based on the provided static analysis. The absence of any reported CVEs, coupled with zero recorded vulnerabilities, suggests a history of secure development or diligent patching by the developers. The static analysis further supports this, showing no dangerous functions, no raw SQL queries, and no external HTTP requests, all of which are positive indicators. The plugin also demonstrates an absence of a significant attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events directly exposed without authentication checks, which is an excellent sign of a well-secured plugin.

However, there are areas for improvement. The most significant concern is the low percentage of properly escaped output (17%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data or dynamic content is not consistently sanitized before being displayed. While the taint analysis shows no unsanitized paths, the static analysis flags this output escaping issue as a concrete risk. The lack of nonce checks on the identified entry points (though there are none) and the single capability check also leave room for potential privilege escalation or unauthorized actions if the attack surface were to grow or be manipulated.

In conclusion, the plugin benefits from a clean vulnerability history and a minimal attack surface. The primary weakness lies in the insufficient output escaping, which represents a tangible XSS risk. While the current lack of exploit data is reassuring, this output escaping issue should be addressed to further solidify the plugin's security.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Social Media Icons Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Social Media Icons Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
1 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

17% escaped6 total outputs
Attack Surface

Social Media Icons Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filterplugins_urlsmc_widget.php:12
actionwidgets_initsmc_widget.php:21
actionplugins_loadedsmc_widget.php:22
actionadmin_print_styles-widgets.phpsmc_widget.php:23
actionadmin_print_scripts-widgets.phpsmc_widget.php:24
actionwp_print_stylessmc_widget.php:26
Maintenance & Trust

Social Media Icons Widget Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedNov 28, 2017
PHP min version
Downloads105K

Community Trust

Rating98/100
Number of ratings8
Active installs1K
Developer Profile

Social Media Icons Widget Developer Profile

arstropica

1 plugin · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Social Media Icons Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-media-icons/styles/smc_admin.css/wp-content/plugins/social-media-icons/js/jquery.livequery.js/wp-content/plugins/social-media-icons/js/tooltip.min.js/wp-content/plugins/social-media-icons/js/smc_admin.js/wp-content/plugins/social-media-icons/styles/smc_front.css
Script Paths
/wp-content/plugins/social-media-icons/js/jquery.livequery.js/wp-content/plugins/social-media-icons/js/tooltip.min.js/wp-content/plugins/social-media-icons/js/smc_admin.js
Version Parameters
social-media-icons/styles/smc_admin.css?ver=social-media-icons/js/jquery.livequery.js?ver=social-media-icons/js/tooltip.min.js?ver=social-media-icons/js/smc_admin.js?ver=social-media-icons/styles/smc_front.css?ver=

HTML / DOM Fingerprints

CSS Classes
SMCWidgetsmc_theme_selectsmc_utilitytooltip
HTML Comments
<!-- tooltip element --><!-- Tooltip --><!-- Widget Options --><!-- Social Media Icons Widget Help -->+1 more
Data Attributes
name="selected_iconset"id="selected_iconset"name="title"id="title"name="smc_widget_update"class="smc_theme_select"
JS Globals
smc_widget_update
FAQ

Frequently Asked Questions about Social Media Icons Widget