
NextScripts: Social Networks Auto-Poster Security & Risk Analysis
wordpress.org/plugins/social-networks-auto-poster-facebook-twitter-gAutomatically publishes blogposts to profiles/pages/groups on Twitter, Google+, Pinterest, LinkedIn, Blogger, Tumblr ... 22 more
Is NextScripts: Social Networks Auto-Poster Safe to Use in 2026?
High Risk
Score 40/100NextScripts: Social Networks Auto-Poster carries significant security risk with 14 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The plugin "social-networks-auto-poster-facebook-twitter-g" version 4.4.7 presents a mixed security posture with several areas of concern that outweigh its strengths. While it utilizes prepared statements for SQL queries and a significant portion of its output is properly escaped, the presence of unprotected AJAX handlers and dangerous functions like `create_function` and `unserialize` indicates potential vulnerabilities. The history of 14 CVEs, with 2 currently unpatched and a prevalence of high and medium severity issues including Deserialization of Untrusted Data, CSRF, and Improper Access Control, strongly suggests a pattern of recurring security weaknesses.
The static analysis reveals an attack surface with 7 AJAX handlers, 7 of which lack authentication checks, posing a significant risk of unauthorized actions. The use of dangerous functions like `unserialize` without proper sanitization on user-supplied data is a critical concern, potentially leading to deserialization vulnerabilities. Furthermore, the taint analysis shows a high number of flows with unsanitized paths (37), although no critical or high severity flows were explicitly identified in this analysis, the sheer volume suggests a potential for overlooked vulnerabilities.
In conclusion, despite some good security practices in place, the significant number of unprotected entry points, the presence of dangerous functions, and the extensive history of vulnerabilities, particularly those related to deserialization and access control, indicate a substantial risk. The plugin requires immediate attention to address unpatched vulnerabilities and to implement robust authentication and input sanitization for all entry points, especially AJAX handlers.
Key Concerns
- Unprotected AJAX handlers
- Dangerous functions present (unserialize, create_function)
- Unpatched CVEs
- High number of unsanitized taint flows
- High severity vulnerability history (3 high)
NextScripts: Social Networks Auto-Poster Security Vulnerabilities
CVEs by Year
Severity Breakdown
14 total CVEs
NextScripts: Social Networks Auto-Poster <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'nxs_fbembed' Shortcode
NextScripts: Social Networks Auto-Poster <= 4.4.7 - Authenticated (Contributor+) PHP Object Injection
NextScripts <= 4.4.6 - Reflected Cross-Site Scripting
NextScripts: Social Networks Auto-Poster <= 4.4.3 - Cross-Site Request Forgery to Arbitrary Post Deletion
NextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information Exposure
NextScripts: Social Networks Auto-Poster <= 4.4.3 - Unauthenticated Stored Cross-Site Scripting via User Agent
NextScripts <= 4.4.2 - Reflected Cross-Site Scripting via code
NextScripts: Social Networks Auto-Poster <= 4.3.25 - Reflected Cross-Site Scripting
NextScripts: Social Networks Auto-Poster <= 4.3.23 - Unauthenticated Stored Cross-Site Scripting
NextScripts: Social Networks Auto-Poster <= 4.3.24 - Arbitrary Post Deletion via Cross-Site Request Forgery
NextScripts: Social Networks Auto-Poster <= 4.3.20 - Reflected Cross-Site Scripting
NextScripts: Social Networks Auto-Poster <= 4.3.17 - Missing Authorization
NextScripts: Social Networks Auto-Poster <= 4.2.7 - Reflected Cross-Site Scripting
NextScripts: Social Networks Auto-Poster <= 3.4.17 - Stored Cross-Site Scripting
NextScripts: Social Networks Auto-Poster Release Timeline
NextScripts: Social Networks Auto-Poster Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
NextScripts: Social Networks Auto-Poster Attack Surface
AJAX Handlers 7
Shortcodes 4
WordPress Hooks 49
Scheduled Events 2
Maintenance & Trust
NextScripts: Social Networks Auto-Poster Maintenance & Trust
Maintenance Signals
Community Trust
NextScripts: Social Networks Auto-Poster Alternatives
WP Tweetbox
wp-tweetbox
WP Tweetbox adds a highly customizable Tweetbox at the end of blog posts and pages. Tweets are branded with your own website URL.
Nevamiss Auto Share
nevamiss
This plugin allows site users to auto-share their site content to authorized social media accounts.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Blog2Social: Social Media Auto Post & Scheduler
blog2social
Automatically share and schedule your WordPress content on top social platforms like Facebook, Instagram, LinkedIn, TikTok, and more.
Jetpack Social
jetpack-social
Write once, publish everywhere. Reach your target audience by sharing your content with Jetpack Social!
NextScripts: Social Networks Auto-Poster Developer Profile
1 plugin · 30K total installs
How We Detect NextScripts: Social Networks Auto-Poster
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-networks-auto-poster-facebook-twitter-g/inc-cl//wp-content/plugins/social-networks-auto-poster-facebook-twitter-g/img//wp-content/plugins/social-networks-auto-poster-facebook-twitter-g/js//wp-content/plugins/social-networks-auto-poster-facebook-twitter-g/css//wp-content/plugins/social-networks-auto-poster-facebook-twitter-g/js/nxssnap-admin.js/wp-content/plugins/social-networks-auto-poster-facebook-twitter-g/js/nxssnap-common.jssocial-networks-auto-poster-facebook-twitter-g/js/nxssnap-admin.js?ver=social-networks-auto-poster-facebook-twitter-g/js/nxssnap-common.js?ver=HTML / DOM Fingerprints
nxs_snap_bodynxssnap_wrap<!-- NextScripts: Social Networks Auto-Poster --><!-- V5 Beta -->data-snap-iddata-snap-post-idwindow.nxs_SNAP_URLwindow.nxs_SNAP_AJAX_URLwindow.nxssnap_admin_obj/wp-json/nxs/v1/settings/wp-json/nxs/v1/accounts/wp-json/nxs/v1/posts[nxs_links]