Social Toolbar Security & Risk Analysis

wordpress.org/plugins/social-toolbar

Plugin for adding a highly customizable toolbar with color selection, social network icons, recent tweet and share buttons into footer.

100 active installs v3.2 PHP + WP 3.3+ Updated Nov 7, 2014
footersocial-iconssocial-networkingtool-bartoolbar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Toolbar Safe to Use in 2026?

Generally Safe

Score 85/100

Social Toolbar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

Based on the static analysis, the "social-toolbar" plugin v3.2 presents a strong initial security posture. The absence of any identified dangerous functions, raw SQL queries, file operations, external HTTP requests, or vulnerability history suggests a well-developed and secure codebase. The plugin also has a minimal attack surface with no reported AJAX handlers, REST API routes, shortcodes, or cron events, further reducing potential points of entry for attackers. This indicates a developer who is mindful of common security pitfalls.

However, a significant concern arises from the complete lack of output escaping, with 0% of 11 total outputs being properly escaped. This represents a critical vulnerability that could allow for Cross-Site Scripting (XSS) attacks if any user-supplied data is reflected in the plugin's output without sanitization. The absence of capability checks and nonce checks also means that any functionality exposed, however small, might not be adequately protected against unauthorized access or misuse. While the plugin has no known CVEs, the unescaped output remains a direct and actionable security risk.

In conclusion, the "social-toolbar" plugin v3.2 exhibits excellent security practices in terms of preventing common code execution vulnerabilities and has a clean vulnerability history. Its primary weakness lies in the critical deficiency of output escaping, which poses a significant XSS risk. The lack of capability and nonce checks, while less severe in the absence of a large attack surface, should also be addressed to ensure robust security.

Key Concerns

  • 0% of outputs properly escaped (XSS risk)
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Social Toolbar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Social Toolbar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped11 total outputs
Attack Surface

Social Toolbar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initsocial-toolbar.php:53
actionadmin_menusocial-toolbar.php:54
actionwp_footersocial-toolbar.php:58
Maintenance & Trust

Social Toolbar Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedNov 7, 2014
PHP min version
Downloads97K

Community Trust

Rating66/100
Number of ratings16
Active installs100
Developer Profile

Social Toolbar Developer Profile

Daddydesign

5 plugins · 240 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Social Toolbar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-toolbar/images/icon.png
Script Paths
http://dashboard.socialtools.fm/socialfm.js

HTML / DOM Fingerprints

JS Globals
social_toolbar_code
FAQ

Frequently Asked Questions about Social Toolbar