
Social Web Suite – Social Media Auto Post, Social Media Auto Publish Security & Risk Analysis
wordpress.org/plugins/social-web-suiteSocial media auto post, social media auto publish, schedule, share, and promote your new, and re-share your old posts to Instagram, X(Twitter), Facebo …
Is Social Web Suite – Social Media Auto Post, Social Media Auto Publish Safe to Use in 2026?
Generally Safe
Score 90/100Social Web Suite – Social Media Auto Post, Social Media Auto Publish has a strong security track record. Known vulnerabilities have been patched promptly.
The social-web-suite plugin version 4.1.12 exhibits a concerning security posture, primarily due to a large number of unprotected AJAX endpoints. While the plugin demonstrates good practices in SQL query handling with 100% prepared statements and a majority of proper output escaping, the sheer volume of unprotected entry points creates a significant attack surface. The single critical taint flow identified, though not explicitly detailed as a critical severity, suggests a potential for path traversal, which is further corroborated by its past vulnerability history involving this specific type of vulnerability.
The vulnerability history, while showing no currently unpatched CVEs, does indicate a past high-severity issue related to Path Traversal. This, combined with the presence of a taint flow with unsanitized paths in the current analysis, strongly suggests that path traversal remains a persistent risk. The plugin's strengths lie in its secure database interactions and a decent percentage of properly escaped output, but these are overshadowed by the immediate risks posed by insecure AJAX handlers and the lingering threat of path-related vulnerabilities.
Key Concerns
- 11 unprotected AJAX handlers
- Flow with unsanitized paths (taint analysis)
- Past high-severity path traversal vulnerability
- 77% properly escaped output
- 2 File operations
Social Web Suite – Social Media Auto Post, Social Media Auto Publish Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Social Web Suite – Social Media Auto Post, Social Media Auto Publish <= 4.1.11 - Directory Traversal to Arbitrary File Download
Social Web Suite – Social Media Auto Post, Social Media Auto Publish Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Social Web Suite – Social Media Auto Post, Social Media Auto Publish Attack Surface
AJAX Handlers 12
WordPress Hooks 24
Maintenance & Trust
Social Web Suite – Social Media Auto Post, Social Media Auto Publish Maintenance & Trust
Maintenance Signals
Community Trust
Social Web Suite – Social Media Auto Post, Social Media Auto Publish Alternatives
ReVivify Social
revivify-social
Plugin that facilitates auto post sharing and scheduling on social networks, keeping the content alive and active.
Jetpack Social
jetpack-social
Write once, publish everywhere. Reach your target audience by sharing your content with Jetpack Social!
Simple Social Media Share Buttons – Social Sharing for Everyone
simple-social-buttons
This Social Share Plugin adds advanced social media sharing buttons to your WordPress sites, such as Facebook, WhatsApp, X, LinkedIn, & Pinterest.
Social Sharing Plugin – Social Warfare
social-warfare
The most beautiful, responsive, lightning fast social share buttons built to boost shares and drive more traffic without slowing down your site.
Revive Social – Social Media Auto Post and Scheduling Automation Plugin
tweet-old-post
Automatically share your WordPress posts on multiple social networks like Facebook, X (Twitter), LinkedIn, Instagram and more.
Social Web Suite – Social Media Auto Post, Social Media Auto Publish Developer Profile
1 plugin · 600 total installs
How We Detect Social Web Suite – Social Media Auto Post, Social Media Auto Publish
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-web-suite/assets/js/backend/script.js/wp-content/plugins/social-web-suite/assets/css/backend/style.css/wp-content/plugins/social-web-suite/assets/js/frontend/script.js/wp-content/plugins/social-web-suite/assets/css/frontend/style.css/wp-content/plugins/social-web-suite/assets/js/backend/script.js/wp-content/plugins/social-web-suite/assets/js/frontend/script.js/wp-content/plugins/social-web-suite/assets/js/backend/script.js?ver=/wp-content/plugins/social-web-suite/assets/css/backend/style.css?ver=/wp-content/plugins/social-web-suite/assets/js/frontend/script.js?ver=/wp-content/plugins/social-web-suite/assets/css/frontend/style.css?ver=HTML / DOM Fingerprints
sws-sharing-buttonsws-settings-tab<!-- The main page for the Social Web Suite --><!-- Post submitbox misc actions for Social Web Suite -->data-sws-post-iddata-sws-noncesws_varsSocialWebSuiteAdmin/wp-json/sws/v1/activate/wp-json/sws/v1/refresh-settings/wp-json/sws/v1/list-categories/wp-json/sws/v1/list-posts/wp-json/sws/v1/list-post-types/wp-json/sws/v1/get-content/wp-json/sws/v1/get-single-post/wp-json/sws/v1/get-post-image/wp-json/sws/v1/unlink/wp-json/sws/v1/ping/wp-json/sws/v1/submit-uninstall-reason/wp-json/sws/v1/notice-rate[social_web_suite_display_buttons]