Social Medias Connect Security & Risk Analysis

wordpress.org/plugins/social-medias-connect

提供wordpress与其它社交媒体(Social Media)网站的账号绑定、连接登陆及文章同步、评论同步转发功能。

10 active installs v2.0.16 PHP + WP 3.1+ Updated Jul 15, 2014
commentfacebookgithubsidebartwitter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Medias Connect Safe to Use in 2026?

Generally Safe

Score 85/100

Social Medias Connect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "social-medias-connect" v2.0.16 plugin exhibits a mixed security posture. On one hand, the absence of known CVEs and unpatched vulnerabilities in its history suggests a generally stable and well-maintained codebase. The use of prepared statements for all SQL queries and a single capability check are positive indicators of secure coding practices. However, significant concerns arise from the static analysis. The most alarming finding is that 100% of the identified output operations (18% of total outputs) are not properly escaped. This presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website's content. Furthermore, all five analyzed taint flows resulted in unsanitized paths, indicating potential vulnerabilities in how external data is processed, although no critical or high-severity issues were flagged in this specific analysis.

The plugin's attack surface appears minimal with zero entry points identified, which is a strong positive. However, the lack of nonce checks on any of its zero AJAX handlers is a missed opportunity for crucial security protection against Cross-Site Request Forgery (CSRF) attacks if any AJAX functionality were to be added or exist without explicit checks. The single file operation also warrants attention, as its context is not provided and could be a vector if not handled securely. The vulnerability history, being entirely empty, is excellent, but it does not negate the identified static code weaknesses that could lead to future vulnerabilities.

Key Concerns

  • 18% of outputs are not properly escaped
  • All 5 taint flows have unsanitized paths
  • No nonce checks on AJAX handlers
  • One file operation found
Vulnerabilities
None known

Social Medias Connect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Social Medias Connect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
85
19 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

18% escaped104 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
admin_quest_action (SMConnect.php:332)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Social Medias Connect Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actioninitSMConnect.php:72
actionwp_headSMConnect.php:73
actionadmin_headSMConnect.php:74
actionlogin_headSMConnect.php:75
actionadmin_menuSMConnect.php:76
actioncomment_postSMConnect.php:77
filterget_avatarSMConnect.php:78
actionlogin_formSMConnect.php:79
actionadd_meta_boxesSMConnect.php:80
actionregister_formSMConnect.php:81
actionlogin_form_loginSMConnect.php:82
actionlostpassword_formSMConnect.php:83
actionlogin_form_registerSMConnect.php:84
actionadmin_noticesSMConnect.php:85
actionlogin_form_lostpasswordSMConnect.php:86
filterplugin_action_linksSMConnect.php:87
actioncomment_formSMConnect.php:142
actioncomment_form_must_log_in_afterSMConnect.php:143
actionwidgets_initwidgets.php:45
Maintenance & Trust

Social Medias Connect Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedJul 15, 2014
PHP min version
Downloads28K

Community Trust

Rating56/100
Number of ratings4
Active installs10
Developer Profile

Social Medias Connect Developer Profile

qiqiboy

4 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Social Medias Connect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-medias-connect/css/smc-admin.css/wp-content/plugins/social-medias-connect/js/smc-admin.js/wp-content/plugins/social-medias-connect/css/smc-style.css
Version Parameters
social-medias-connect/css/smc-admin.css?s=social-medias-connect/js/smc-admin.js?s=social-medias-connect/css/smc-style.css?s=

HTML / DOM Fingerprints

CSS Classes
smc-admin-css
HTML Comments
<!-- start social medias connect V--> <!-- end social medias connect V
Data Attributes
smcRedirect_urismcWeibo
JS Globals
window.smcAction
FAQ

Frequently Asked Questions about Social Medias Connect