
Sociallist Security & Risk Analysis
wordpress.org/plugins/sociallist-social-bookmarking-widgetAllow websurfers to save and share interesting pages. The plugin appends widget for popular social bookmarking sites to the end of blog’s posts.
Is Sociallist Safe to Use in 2026?
Generally Safe
Score 85/100Sociallist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sociallist-social-bookmarking-widget" plugin, version 1.5.1, presents a mixed security profile. On the positive side, the plugin boasts a completely clean vulnerability history with no known CVEs, indicating a strong track record of security. The absence of any declared dangerous functions, SQL queries without prepared statements, and external HTTP requests are also positive signs of secure coding practices. However, significant concerns arise from the static analysis. A critical finding is that 100% of the 12 output operations are not properly escaped. This means that any user-supplied data that is displayed by the plugin could potentially be exploited through cross-site scripting (XSS) attacks. Furthermore, the taint analysis revealed two flows with unsanitized paths, which could be indicative of potential vulnerabilities related to file path manipulation or directory traversal if not handled carefully, though the analysis did not flag these as critical or high severity. The lack of nonce and capability checks on the identified entry points, though currently zero, could become a risk if the plugin were to be extended or if new entry points are introduced without proper authentication and authorization measures.
In conclusion, while the plugin has a strong history of being vulnerability-free and avoids common pitfalls like raw SQL and dangerous functions, the complete lack of output escaping is a glaring security weakness that leaves it susceptible to XSS attacks. The unsanitized paths also warrant attention. Developers should prioritize addressing the output escaping issue to mitigate the risk of XSS. The absence of authentication checks, while not currently exploitable due to a zero attack surface, is a potential future risk that should be considered as the plugin evolves.
Key Concerns
- 0% of outputs properly escaped
- 2 flows with unsanitized paths
- 0 capability checks found
- 0 nonce checks found
Sociallist Security Vulnerabilities
Sociallist Code Analysis
Output Escaping
Data Flow Analysis
Sociallist Attack Surface
WordPress Hooks 5
Maintenance & Trust
Sociallist Maintenance & Trust
Maintenance Signals
Community Trust
Sociallist Alternatives
Sociable RE
sociable-re
Добавляет кнопки для публикации ссылок в соц. сетях на страницы блога.
Social Profilr
social-profilr-display-social-network-profile
Sidebar Widget To Display Eye Candy Icon to Display Your Social Network Profile
České a slovenské linkovací služby
ceske-a-slovenske-linkovaci-sluzby
České a slovenské linkovací služby jako doplněk pluginu Sociable.
SocioFluid
sociofluid
SocioFluid is a social bookmarking plugin for wordpress. For details you can check the <a href="http://www.improveseo.info/SocioFluid">SocioFluid Homepage</a>.
Add Social Bookmarks
wp-add-social-bookmarks
WP Add Social Bookmarks + Animation effect is a plug-in designed to add major social bookmarks to your website.
Sociallist Developer Profile
2 plugins · 20 total installs
How We Detect Sociallist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sociallist-social-bookmarking-widget/sociallist.css/wp-content/plugins/sociallist-social-bookmarking-widget/sociallist-admin.css/wp-content/plugins/sociallist-social-bookmarking-widget/description_selection.jshttp://sociallist.org/widget.jsHTML / DOM Fingerprints
sociallistsociallist_tagline<!-- SocialList.org BEGIN --><!-- SocialList.org END -->data-sociallist_urldata-sociallist_titledata-sociallist_textdata-sociallist_tagssociallist_<div class="sociallist">
<span class="sociallist_tagline">