
Social Media Shortcodes Security & Risk Analysis
wordpress.org/plugins/social-media-shortcodesRegisters shortcodes for your posts, pages, or post types that display user profile links to various social media websites.
Is Social Media Shortcodes Safe to Use in 2026?
Generally Safe
Score 98/100Social Media Shortcodes has a strong security track record. Known vulnerabilities have been patched promptly.
The "social-media-shortcodes" plugin v1.3.2 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and proper output escaping indicate robust coding practices in these areas. Furthermore, there are no identified flows with unsanitized paths in the taint analysis, and the attack surface appears to be minimal with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks. The plugin also does not make external HTTP requests, which is a positive security control.
However, the vulnerability history presents a significant concern. The plugin has a history of two known medium-severity CVEs, both related to Cross-site Scripting (XSS). While there are currently no unpatched vulnerabilities, this pattern suggests that previous versions were susceptible to XSS, and vigilance is required to ensure that future updates fully mitigate these risks. The lack of nonce and capability checks in the static analysis, while not directly indicating a current vulnerability, represents a missed opportunity for defense-in-depth, especially if new entry points were ever introduced or if the existing zero entry points were to be misconfigured by the user. The plugin's strength lies in its minimal attack surface and secure handling of database queries and output, but its past vulnerability trends necessitate careful monitoring and a cautious approach to its deployment.
Key Concerns
- History of 2 medium XSS vulnerabilities
- 0 capability checks detected
- 0 nonce checks detected
Social Media Shortcodes Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Social Media Shortcodes <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Social Media Shortcodes <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Social Media Shortcodes Code Analysis
Output Escaping
Social Media Shortcodes Attack Surface
WordPress Hooks 1
Maintenance & Trust
Social Media Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Social Media Shortcodes Alternatives
Popular Brand Icons – Simple Icons
simple-icons
An easy to use lightweight SVG icons plugin with over 1500+ brand icons. Use these icons in your menus, widgets, posts, or pages.
Bamboo Social
bamboo-social
This plugin provides a widget and a shortcode for generating social media icons that link to the relevent social media accounts.
Social Links Manager
social-links-manager
A plugin to manage social media links and display them on your site using a shortcode. Links left empty will not be displayed.
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Astra Widgets
astra-widgets
Quickest solution to add widgets like Address, Social Profiles and List icons on a website built with Astra.
Social Media Shortcodes Developer Profile
9 plugins · 370 total installs
How We Detect Social Media Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
smscdeviantart_smscdigg_smscdribbble_smscetsy_smscfacebook_smscflickr_smscflipboard_smsc+21 moredata-service<a href="title=" class=" target="