SOCMEN Security & Risk Analysis

wordpress.org/plugins/socmen

Easy add social buttons in menu bar...

10 active installs v2.1.0 PHP + WP 4.1+ Updated Jun 3, 2018
facebookgoogleinstagrampinteresttwitter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SOCMEN Safe to Use in 2026?

Generally Safe

Score 85/100

SOCMEN has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'socmen' plugin v2.1.0 demonstrates a strong initial security posture, as indicated by the static analysis. The absence of any identified entry points like AJAX handlers, REST API routes, or shortcodes is a significant positive. Furthermore, the code shows no dangerous functions, no raw SQL queries, and no file operations, all of which are excellent security practices. The high percentage of properly escaped output suggests a good understanding of preventing cross-site scripting (XSS) vulnerabilities. The lack of any recorded vulnerabilities in its history further reinforces this positive outlook.

However, the analysis does reveal some areas of concern. The complete absence of nonce checks and capability checks is a critical weakness. This means that even if there were entry points (which there aren't currently), they would be entirely unprotected against unauthorized access and manipulation. The zero taint flows analyzed is also noteworthy; while it might indicate clean code, it could also mean the analysis depth was insufficient to uncover potential issues. A more comprehensive taint analysis would provide greater confidence. Overall, while the current version of 'socmen' appears robust due to its minimal attack surface and good output escaping, the lack of essential security checks like nonces and capability checks represents a significant potential risk if any new entry points are introduced in future updates.

In conclusion, 'socmen' v2.1.0 benefits from a very small attack surface and good output escaping practices, leading to a generally positive security profile. Its vulnerability-free history is also reassuring. The primary weaknesses lie in the complete absence of nonce and capability checks, which, while not exploitable with the current zero entry points, creates a substantial latent risk. Future development should prioritize implementing these critical security controls.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
  • Limited Taint Analysis Depth
  • 30% of Outputs Unescaped
Vulnerabilities
None known

SOCMEN Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SOCMEN Release Timeline

v2.0.1
v2.0.0
v1.0.1
Code Analysis
Analyzed Mar 17, 2026

SOCMEN Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
48 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

70% escaped69 total outputs
Attack Surface

SOCMEN Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionwp_enqueue_scriptszmen.php:13
actionadmin_print_styleszmen.php:19
actionadmin_menuzmen.php:28
actionadmin_initzmen.php:29
actionwp_enqueue_scriptszmen.php:233
actionwp_footerzmen.php:367
actionwp_headzmen.php:379
actionadmin_initzmen.php:435
Maintenance & Trust

SOCMEN Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJun 3, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

SOCMEN Developer Profile

webmaric

3 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SOCMEN

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/socmen/css/style.css/wp-content/plugins/socmen/css/zmenadmin.css

HTML / DOM Fingerprints

CSS Classes
wrap1okvirnaslovforma1
Data Attributes
name="zm_fb_option"name="zm_tw_option"name="zm_in_option"name="zm_pt_option"name="zm_gp_option"name="zm_ld_option"+19 more
FAQ

Frequently Asked Questions about SOCMEN