
SocialWiggle Security & Risk Analysis
wordpress.org/plugins/social-wiggleDisplay your social network profiles using catchy looking Metro tiles that wiggle to catch your visitor's attention
Is SocialWiggle Safe to Use in 2026?
Generally Safe
Score 85/100SocialWiggle has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "social-wiggle" v0.8.2 plugin exhibits a generally strong security posture, particularly in its handling of SQL queries and its lack of direct external interactions. The absence of known vulnerabilities, CVEs, and a clean vulnerability history are positive indicators. Furthermore, the static analysis reveals no discernible attack surface through common entry points like AJAX, REST API, shortcodes, or cron events, and importantly, no unprotected entry points were identified. Taint analysis also shows no critical or high severity flows, suggesting a lack of immediately exploitable code injection or data manipulation vulnerabilities.
However, there are significant concerns. The presence of two instances of the "create_function" dangerous function is a major red flag. While no taint flows were identified as directly originating from these, "create_function" is deprecated and known to be a potential source of vulnerabilities if not handled with extreme care, especially in older PHP versions. Additionally, a very low percentage (12%) of output escaping indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. The extensive unescaped output suggests that user-supplied or dynamically generated data is likely being rendered directly into the HTML without proper sanitization, making the plugin susceptible to XSS attacks.
In conclusion, while the plugin has a clean history and a minimal attack surface, the identified use of a dangerous function and the pervasive lack of output escaping represent critical weaknesses. The security of "social-wiggle" v0.8.2 is compromised by these two factors, despite its otherwise commendable adherence to some security best practices.
Key Concerns
- Dangerous functions found (create_function)
- Low output escaping percentage (12%)
SocialWiggle Security Vulnerabilities
SocialWiggle Code Analysis
Dangerous Functions Found
Output Escaping
SocialWiggle Attack Surface
WordPress Hooks 15
Maintenance & Trust
SocialWiggle Maintenance & Trust
Maintenance Signals
Community Trust
SocialWiggle Alternatives
Social Network Widget
social-network-widget
A simple customizable social networks widget for your sidebars.
Social Media Share & Widget
social-media-share-and-widget
Social Icons Widget to displays links to social sharing websites. Currently its Supports Only 15 sites.
MM Social
mm-social
Place you social profile at your website's anywhere using shortcode : [MM_SOCIAL_ICON]
Simple Social Icons
simple-social-icons
This plugin provides two ways to display social icons: a traditional widget (available on all WordPress versions) and block variations for the core So …
Lightweight Social Icons
lightweight-social-icons
Looking to add simple social icons to your widget areas? Choose the size and color of your icons, and then choose from 47 different social profiles.
SocialWiggle Developer Profile
6 plugins · 7K total installs
How We Detect SocialWiggle
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-wiggle/socialwiggle.css/wp-content/plugins/social-wiggle/socialwiggle.js/wp-content/plugins/social-wiggle/jquery.tablednd.0.7.min.js/wp-content/plugins/social-wiggle/socialwiggle.js/wp-content/plugins/social-wiggle/jquery.tablednd.0.7.min.jssocialwiggle.css?ver=socialwiggle.js?ver=HTML / DOM Fingerprints
socwig-widgetsocwig_linksdata-demo-styledata-demo-wigglesocialwiggle[socialwiggle][socialwiggle_links]