Social Tools Security & Risk Analysis

wordpress.org/plugins/social-tools

The plugin creates three widgets for displaying various social media sites: Social Icons, Facebook Likebox, Instagram Feed.

10 active installs v1.0.1 PHP 5.6+ WP 4.9.5+ Updated Mar 10, 2021
social-iconssocial-linkssocial-mediasocial-networkwp-social-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Tools Safe to Use in 2026?

Generally Safe

Score 85/100

Social Tools has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'social-tools' plugin v1.0.1 demonstrates a generally good security posture based on the provided static analysis. The plugin does not appear to have critical vulnerabilities such as dangerous functions, unsanitized taint flows, or raw SQL queries. The significant majority of output is properly escaped, and there's evidence of capability checks, which are positive security indicators. The plugin also avoids bundling external libraries and making unnecessary external HTTP requests. The absence of any recorded vulnerabilities or CVEs further strengthens this assessment, suggesting a history of secure development or diligent patching by developers. However, a notable area for improvement is the complete lack of nonce checks. While the direct attack surface of AJAX handlers and REST API routes is zero, this absence of nonces is a significant weakness that could be exploited if any new entry points are introduced or if existing shortcodes evolve to interact with user-submitted data in ways not immediately obvious from this analysis. The presence of shortcodes also represents potential input vectors that require careful handling, even without explicit taint flow issues detected in this specific analysis.

Key Concerns

  • Missing nonce checks on entry points
  • 78% output escaping is not 100%
Vulnerabilities
None known

Social Tools Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Social Tools Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
41
147 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

78% escaped188 total outputs
Attack Surface

Social Tools Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[adswst_social_icons] core\init.php:41
[adswst_instagram] core\init.php:64
WordPress Hooks 5
actioninitalids-social-tools.php:25
actionwidgets_initcore\init.php:9
actionadmin_menucore\setup.php:34
actionadmin_enqueue_scriptswidgets\widget-social-icons.php:17
actionadmin_footer-widgets.phpwidgets\widget-social-icons.php:18
Maintenance & Trust

Social Tools Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 10, 2021
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Social Tools Developer Profile

desishe

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Social Tools

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-tools/widgets/widget-facebook.php/wp-content/plugins/social-tools/widgets/widget-instagram.php/wp-content/plugins/social-tools/widgets/widget-social-icons.php
Version Parameters
ver=1.0.1

HTML / DOM Fingerprints

CSS Classes
adswst_facebook_likebox_widgetadswst_instagram_widgetadswst_social_icons_widget
Data Attributes
data-hrefdata-small-headerdata-adapt-container-widthdata-hide-coverdata-show-facepiledata-show-posts
JS Globals
ADSWST_VERSIONADSWST_PATHADSWST_URL
FAQ

Frequently Asked Questions about Social Tools