
Social News Center Security & Risk Analysis
wordpress.org/plugins/social-news-centerDisplay latest Posts from social media sites like Facebook, Instagram & Twitter. Perform actions such as view profiles, Like, Share, Favorite & …
Is Social News Center Safe to Use in 2026?
Generally Safe
Score 85/100Social News Center has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "social-news-center" plugin version 0.0.8 exhibits a significantly concerning security posture due to a large number of unprotected entry points. With 32 out of 37 total entry points lacking any authentication or capability checks, this plugin is highly susceptible to unauthorized access and manipulation. The presence of the "unserialize" dangerous function, while not directly linked to a taint flow in this analysis, is a known vector for remote code execution if user-supplied data is deserialized without proper sanitization. The static analysis also reveals that 100% of SQL queries utilize prepared statements, which is a positive indicator for preventing SQL injection. However, the output escaping is only at 45%, suggesting a potential for cross-site scripting (XSS) vulnerabilities. The absence of any recorded vulnerabilities in its history is a strength, implying a good track record. Despite the positive aspect of secure SQL handling and the lack of known CVEs, the overwhelming number of unprotected AJAX handlers and the presence of a dangerous function like unserialize, coupled with insufficient output escaping, presents a substantial risk. This plugin requires immediate attention to secure its entry points and review output sanitization practices.
Key Concerns
- AJAX handlers unprotected
- Dangerous function unserialize
- Low output escaping percentage
- Missing nonce checks on AJAX
- Missing capability checks
Social News Center Security Vulnerabilities
Social News Center Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Social News Center Attack Surface
AJAX Handlers 32
Shortcodes 5
WordPress Hooks 6
Maintenance & Trust
Social News Center Maintenance & Trust
Maintenance Signals
Community Trust
Social News Center Alternatives
SoGrid Lite
sogrid-lite-social-networks-posts-grid
SoGrid is a WordPress plugin that displays your social network posts / feed in a functional grid.
Open Graph and Twitter Card Tags
wonderm00ns-simple-facebook-open-graph-tags
Improve social media sharing by inserting Facebook Open Graph, Twitter Card, and SEO Meta Tags on your WordPress website pages, posts, WooCommerce pro …
Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds
facebook-pagelike-widget
Floating Social Media Icons, Sticky Share Buttons, Facebook Feeds, & Popup builder. Also, create Call, Email, SMS, & Contact buttons to increa …
OG — Better Share on Social Media
og
The simple method to add Open Graph metadata to your entries so that they look great when shared on sites.
Social Media Widget
social-media-widget
Adds links to all of your social media and sharing site profiles. Tons of icons come in 3 sizes, 4 icon styles, and 4 animations.
Social News Center Developer Profile
1 plugin · 10 total installs
How We Detect Social News Center
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-news-center/css/magnific-popup.css/wp-content/plugins/social-news-center/css/style.css/wp-content/plugins/social-news-center/js/isotope.pkgd.min.js/wp-content/plugins/social-news-center/js/imagesloaded.pkgd.min.js/wp-content/plugins/social-news-center/js/jquery.magnific-popup.min.js/wp-content/plugins/social-news-center/js/functions.js/wp-content/plugins/social-news-center/js/functions-wp.js/wp-content/plugins/social-news-center/js/facebook.js+2 morejs/isotope.pkgd.min.jsjs/imagesloaded.pkgd.min.jsjs/jquery.magnific-popup.min.jsjs/functions.jsjs/functions-wp.jsjs/facebook.js+2 moreHTML / DOM Fingerprints
FBthe_ajax_scriptsnc_doCheckLoginStatussnc_getSocialMediaPostssnc_doEmptyCache_callbacksnc_getFacebookPosts_callback/wp-json/snc/v1/data<div id="fb-root"></div><script type="text/javascript">window.fbAsyncInit = function() {FB.init({appId