
Socially Social Bookmaring Widget Security & Risk Analysis
wordpress.org/plugins/socially-social-bookmarking-widgetSocailly is an easy to use sidebar widget that displays Facebook, Twitter, Digg, StumbleUpon, YouTube & RSS icons.
Is Socially Social Bookmaring Widget Safe to Use in 2026?
Generally Safe
Score 85/100Socially Social Bookmaring Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The socially-social-bookmarking-widget plugin v3.0 presents a mixed security posture. While the absence of known CVEs and the complete utilization of prepared statements for SQL queries are positive indicators, significant concerns arise from the static analysis.
The code analysis reveals a critical issue with the presence of `create_function`, a deprecated and often insecure PHP function that can lead to code injection vulnerabilities if user input is ever passed to it without proper sanitization. Furthermore, a substantial weakness lies in the complete lack of output escaping, meaning any data displayed by the plugin is vulnerable to cross-site scripting (XSS) attacks. The absence of nonce and capability checks on any potential entry points, though the attack surface is currently reported as zero, creates a latent risk should new functionalities be added without these crucial security layers.
Given the plugin's history of zero recorded vulnerabilities, it might suggest a low likelihood of active exploitation or a lack of discovery. However, the code analysis itself flags inherent risks that do not depend on historical exploitability. The lack of output escaping is a fundamental security flaw that should be addressed immediately, as it exposes users to common web attacks. The presence of `create_function` is another significant concern that necessitates remediation. The plugin's strengths lie in its current lack of known exploits and its proper handling of SQL, but these are overshadowed by critical code-level weaknesses.
Key Concerns
- create_function used
- 100% of outputs not properly escaped
- 0 capability checks
- 0 nonce checks
Socially Social Bookmaring Widget Security Vulnerabilities
Socially Social Bookmaring Widget Code Analysis
Dangerous Functions Found
Output Escaping
Socially Social Bookmaring Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Socially Social Bookmaring Widget Maintenance & Trust
Maintenance Signals
Community Trust
Socially Social Bookmaring Widget Alternatives
CMS Vote Up Social CMS News
cms-vote-up-social-cms-news-button
A must have social CMS website news button for Wordpress user (blogger). This button will enable your visitor to vote for your website's article …
Social Media Icons Widget
social-media-icons
Developed at NCI.
Naked Social Share
naked-social-share
Simple, unstyled social share icons for theme designers.
Simple Socnets
simple-socnets
This plugin was built by the Maine WordPress Meetup group to make it really easy to add social network icons to your posts.
Social Media Manager
social-media-manager
Providing the ability to manage how social media sites see your blog or website. Manage your facebook sharing image, update twitter status for multipl …
Socially Social Bookmaring Widget Developer Profile
2 plugins · 310 total installs
How We Detect Socially Social Bookmaring Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/socially-social-bookmarking-widget/icons/fb.png/wp-content/plugins/socially-social-bookmarking-widget/icons/twt.png/wp-content/plugins/socially-social-bookmarking-widget/icons/su.png/wp-content/plugins/socially-social-bookmarking-widget/icons/digg.png/wp-content/plugins/socially-social-bookmarking-widget/icons/youtube.png/wp-content/plugins/socially-social-bookmarking-widget/icons/rss.pngHTML / DOM Fingerprints
socially_widgetid="socially_widget"id="socially_widget"name="socially_widget"for="socially_widget"id="socially_widget"name="socially_widget"+16 more