
Social Plugin – Metadata Security & Risk Analysis
wordpress.org/plugins/social-page-metadataDisplay meta information from the social network "Facebook" containing Business Hours, About details, Last public post, etc...
Is Social Plugin – Metadata Safe to Use in 2026?
Generally Safe
Score 92/100Social Plugin – Metadata has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "social-page-metadata" v1.1.5 plugin exhibits a mixed security posture. While it demonstrates good practices in SQL query handling and avoids known vulnerabilities, significant concerns arise from its attack surface and output escaping mechanisms. The presence of six unprotected AJAX handlers creates a considerable entry point for potential attacks, as these can be invoked without proper user authentication or authorization checks. The taint analysis, though showing no critical or high severity flows, did identify seven flows with unsanitized paths, which, when combined with unprotected AJAX endpoints, could lead to unpredictable behavior or vulnerabilities if these paths are exploited.
The lack of any recorded historical vulnerabilities is a positive indicator, suggesting a generally stable codebase or a history of prompt patching. However, this does not negate the immediate risks identified in the static analysis. The plugin's strength lies in its secure SQL implementation and absence of known CVEs. Conversely, its weaknesses are the significant number of unprotected AJAX endpoints and the high percentage of improperly escaped output, which could lead to cross-site scripting (XSS) vulnerabilities. A balanced conclusion is that while the plugin appears to have a clean history, the current version presents immediate risks due to its attack surface and output handling that require attention.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Low percentage of properly escaped output
- Zero nonce checks on AJAX handlers
Social Plugin – Metadata Security Vulnerabilities
Social Plugin – Metadata Code Analysis
Output Escaping
Data Flow Analysis
Social Plugin – Metadata Attack Surface
AJAX Handlers 6
Shortcodes 4
WordPress Hooks 4
Maintenance & Trust
Social Plugin – Metadata Maintenance & Trust
Maintenance Signals
Community Trust
Social Plugin – Metadata Alternatives
DUZZ
duzz-seo
DUZZ adds meta data for SEO and Facebook shares as well as analytics and webmaster tools code to your site and much more.
Smart Slider 3
smart-slider-3
Responsive slider plugin to create sliders in visual editor easily. Build beautiful image slider, layer slider, video slider, post slider, and more.
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Meta for WooCommerce
facebook-for-woocommerce
Get the Official Meta for WooCommerce plugin for powerful ways to help grow your business.
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty
chaty
WhatsApp chat, Facebook Messenger, Telegram, TikTok, Instagram, Email, Line, WeChat Phone call, SMS, 20+ live chat icons & WhatsApp chat pop up 💬
Social Plugin – Metadata Developer Profile
3 plugins · 50 total installs
How We Detect Social Plugin – Metadata
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-page-metadata/styles/style.css/wp-content/plugins/social-page-metadata/scripts/init.js/wp-content/plugins/social-page-metadata/scripts/widget.js/wp-content/plugins/social-page-metadata/scripts/init.js/wp-content/plugins/social-page-metadata/scripts/widget.jssocial-page-metadata/style.css?ver=social-page-metadata/scripts/init.js?ver=social-page-metadata/scripts/widget.js?ver=HTML / DOM Fingerprints
social-plugin-metadata-emptysocial_plugin[social-businesshours[social-about[social-lastpost[social-events