
Social Media Popup Security & Risk Analysis
wordpress.org/plugins/social-media-popup-freePlugin creates the popup window with most popular social media widgets
Is Social Media Popup Safe to Use in 2026?
Generally Safe
Score 85/100Social Media Popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "social-media-popup-free" plugin v0.7.5 presents a generally good security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are all prepared, and there are no file operations or external HTTP requests, all of which are positive indicators. The plugin also implements capability checks, which is a good practice for securing administrative actions.
However, there are some areas of concern. A significant portion (50%) of output is not properly escaped, posing a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is ever rendered directly. Additionally, the complete lack of nonce checks across the entire plugin, especially given the presence of capability checks, could indicate a weakness in securing form submissions or AJAX requests, though no such entry points were identified in the static analysis. The absence of any identified taint flows or CVEs is reassuring, but the unescaped output remains a notable vulnerability.
Overall, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the unescaped output and the complete absence of nonce checks, even without identified entry points, suggest a need for further code review. The lack of any historical vulnerabilities might indicate a mature and stable codebase, or simply a lack of past rigorous security audits. Strengthening output escaping and considering nonce implementation for any future additions would improve its security.
Key Concerns
- 50% of output is not properly escaped
- 0 nonce checks implemented
Social Media Popup Security Vulnerabilities
Social Media Popup Release Timeline
Social Media Popup Code Analysis
Output Escaping
Social Media Popup Attack Surface
WordPress Hooks 7
Maintenance & Trust
Social Media Popup Maintenance & Trust
Maintenance Signals
Community Trust
Social Media Popup Alternatives
Open Graph and Twitter Card Tags
wonderm00ns-simple-facebook-open-graph-tags
Improve social media sharing by inserting Facebook Open Graph, Twitter Card, and SEO Meta Tags on your WordPress website pages, posts, WooCommerce pro …
Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds
facebook-pagelike-widget
Floating Social Media Icons, Sticky Share Buttons, Facebook Feeds, & Popup builder. Also, create Call, Email, SMS, & Contact buttons to increa …
OG — Better Share on Social Media
og
The simple method to add Open Graph metadata to your entries so that they look great when shared on sites.
Social Media Widget
social-media-widget
Adds links to all of your social media and sharing site profiles. Tons of icons come in 3 sizes, 4 icon styles, and 4 animations.
Social Media Feather | social media sharing
social-media-feather
Lightweight, modern looking and effective social media sharing and profile buttons and icons. All your social media needs in 1 easy package!
Social Media Popup Developer Profile
3 plugins · 5K total installs
How We Detect Social Media Popup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-media-popup-free/js/social-media-popup-free.js/wp-content/plugins/social-media-popup-free/css/social-media-popup-free.css/wp-content/plugins/social-media-popup-free/js/admin.js/wp-content/plugins/social-media-popup-free/js/social-media-popup-free.js/wp-content/plugins/social-media-popup-free/js/admin.jssocial-media-popup-free/js/social-media-popup-free.js?ver=social-media-popup-free/css/social-media-popup-free.css?ver=social-media-popup-free/js/admin.js?ver=HTML / DOM Fingerprints
smp_wrappersmp_tab_container<!-- social-media-popup-free --><!-- social-media-popup-free.php --><!-- social-media-popup.class.php -->data-scp-prefixdata-scp-page-urlscp_vars