Social Subscribe Box Security & Risk Analysis

wordpress.org/plugins/social-subscribe-box

Simple Mailchimp newsletter subscription slide-out box with social profile links.

10 active installs v1.0.0 PHP 5.3.0+ WP 4.7+ Updated Mar 19, 2021
mailchimpmailchimp-subscriptionnewsletternewsletter-subscriptionslideout
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Subscribe Box Safe to Use in 2026?

Generally Safe

Score 85/100

Social Subscribe Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "social-subscribe-box" plugin version 1.0.0 demonstrates a generally good security posture with several positive indicators. Notably, all identified entry points (AJAX handlers) are protected by capability checks, and SQL queries are exclusively performed using prepared statements, which significantly mitigates the risk of SQL injection vulnerabilities. The plugin also incorporates nonce checks, further enhancing its resistance to common WordPress attacks. The absence of known CVEs and a clean vulnerability history are also strong positive signs.

However, a critical concern lies in the presence of the `unserialize` function, which is notoriously dangerous when handling user-controlled input. While no taint flows were detected in this static analysis, the potential for a deserialization vulnerability exists if the data being unserialized is not strictly controlled or validated. Additionally, while the majority of output is properly escaped, the 24% that is not could still lead to cross-site scripting (XSS) vulnerabilities if that output contains user-supplied data. The single file operation also warrants scrutiny, though its context is not provided.

In conclusion, the plugin has a solid foundation with strong adherence to best practices like prepared statements and capability checks. The lack of past vulnerabilities is encouraging. The primary area of attention for improvement is the safe handling of the `unserialize` function to prevent potential deserialization exploits and to ensure all output is consistently escaped to eliminate XSS risks.

Key Concerns

  • Use of unserialize function
  • Unescaped output present (24% of 85)
Vulnerabilities
None known

Social Subscribe Box Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Social Subscribe Box Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
20
65 escaped
Nonce Checks
2
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

unserialize$lists = unserialize( get_transient( 'pt_social_subscribe_mailing_list' ) );admin\class-social-subscribe-box-settings.php:293

Output Escaping

76% escaped85 total outputs
Attack Surface

Social Subscribe Box Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_pt_settings_create_pageadmin\pt-settings\src\class-ajax-handler.php:31
noprivwp_ajax_ptssbox_subscribesocial-subscribe-box.php:93
authwp_ajax_ptssbox_subscribesocial-subscribe-box.php:94
WordPress Hooks 10
actioncustomize_registeradmin\class-social-subscribe-box-customizer.php:50
actioncustomize_preview_initadmin\class-social-subscribe-box-customizer.php:52
actionwp_headadmin\class-social-subscribe-box-customizer.php:54
actionadmin_initadmin\class-social-subscribe-box-settings.php:43
actionadmin_menuadmin\class-social-subscribe-box-settings.php:44
actionadmin_enqueue_scriptsadmin\pt-settings\pt-settings-loader.php:89
actionplugins_loadedsocial-subscribe-box.php:89
actionplugins_loadedsocial-subscribe-box.php:90
actionwp_enqueue_scriptssocial-subscribe-box.php:97
actionwp_footersocial-subscribe-box.php:100
Maintenance & Trust

Social Subscribe Box Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.0
Last updatedMar 19, 2021
PHP min version5.3.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Social Subscribe Box Developer Profile

Brajesh Singh

12 plugins · 2K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
3856 days
View full developer profile
Detection Fingerprints

How We Detect Social Subscribe Box

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-subscribe-box/assets/css/social-subscribe-box.css/wp-content/plugins/social-subscribe-box/assets/js/social-subscribe-box.js/wp-content/plugins/social-subscribe-box/vendors/jquery-tab-slide-out/jquery.tabSlideOut.css/wp-content/plugins/social-subscribe-box/vendors/jquery-cookie.js/wp-content/plugins/social-subscribe-box/vendors/jquery-tab-slide-out/jquery.tabSlideOut.js
Script Paths
/wp-content/plugins/social-subscribe-box/assets/js/social-subscribe-box.js
Version Parameters
social-subscribe-box/assets/css/social-subscribe-box.css?ver=social-subscribe-box/assets/js/social-subscribe-box.js?ver=

HTML / DOM Fingerprints

CSS Classes
pt-social-subscribe-box-wrappt-social-subscribe-box-content
Data Attributes
data-ptssbox-ajax-urldata-ptssbox-tab-title-closeddata-ptssbox-tab-title-opendata-ptssbox-tab-locationdata-ptssbox-tab-offsetdata-ptssbox-tab-offset-from
JS Globals
PTSocailSubscribeBox
FAQ

Frequently Asked Questions about Social Subscribe Box