Social Repeater Widget Security & Risk Analysis

wordpress.org/plugins/social-repeater-widget

A simple and nice plugin to add simple social icons and profile link, which allows you to easily add the social profile to your site widget area.

0 active installs v1.0.0 PHP 7.0+ WP 4.8+ Updated Dec 3, 2020
repeatablesocialsocial-icon-widgetsocial-linkssocial-profiles
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Repeater Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Social Repeater Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "social-repeater-widget" plugin, version 1.0.0, exhibits a strong static security posture. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code analysis reveals no dangerous functions, no raw SQL queries (all utilize prepared statements), no file operations, and no external HTTP requests. The lack of taint analysis findings further strengthens this positive outlook, indicating no identifiable flows with unsanitized paths. The plugin also has no known vulnerability history, which is a significant indicator of good security practices over time.

However, the analysis does highlight a notable concern: a low percentage of properly escaped output (24%). This suggests a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is directly rendered without adequate sanitization. The absence of nonce checks and capability checks, while not directly exploitable due to the limited attack surface, represents missed security best practices. In conclusion, while the plugin has a clean slate and a minimal attack surface, the insufficient output escaping is a tangible risk that warrants attention. Addressing this would move the plugin towards a more robust security profile.

Key Concerns

  • Low percentage of properly escaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Social Repeater Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Social Repeater Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

24% escaped33 total outputs
Attack Surface

Social Repeater Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuinc\SocialRepeaterSettings.php:15
actionadmin_initinc\SocialRepeaterSettings.php:16
actionwp_enqueue_scriptssocial-repeater-widget.php:38
actionadmin_enqueue_scriptssocial-repeater-widget.php:39
actionwidgets_initsocial-repeater-widget.php:40
actionplugins_loadedsocial-repeater-widget.php:41
Maintenance & Trust

Social Repeater Widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedDec 3, 2020
PHP min version7.0
Downloads883

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Social Repeater Widget Developer Profile

Shabab Ahmed

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Social Repeater Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-repeater-widget/assets/public/css/style.css/wp-content/plugins/social-repeater-widget/assets/public/js/script.js/wp-content/plugins/social-repeater-widget/assets/admin/js/admin.js
Script Paths
//cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css

HTML / DOM Fingerprints

CSS Classes
srw-social-icons
Data Attributes
data-widget-id
FAQ

Frequently Asked Questions about Social Repeater Widget