
StatusNet Widget Security & Risk Analysis
wordpress.org/plugins/statusnet-widgetStatusNet Widget provides a widget to pull your status from StatusNet sites like identi.ca. Multiple sources are supported.
Is StatusNet Widget Safe to Use in 2026?
Generally Safe
Score 100/100StatusNet Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The statusnet-widget plugin version 0.5 exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities or CVEs, and it demonstrates good practice by using prepared statements for all SQL queries. It also doesn't perform file operations or external HTTP requests, reducing common attack vectors. However, significant concerns arise from the static analysis. The presence of a `create_function` call is a direct indicator of potential for code injection vulnerabilities if user input is ever used within it. Furthermore, a substantial portion (71%) of output is not properly escaped, posing a clear risk of Cross-Site Scripting (XSS) vulnerabilities, especially if any dynamic content is displayed to users without sanitization. The lack of nonce checks and capability checks across all identified entry points (even though the attack surface appears small) is a critical oversight, leaving any potential future exposed functionalities vulnerable to CSRF and unauthorized access.
The absence of any historical vulnerabilities is encouraging, suggesting that past development might have been diligent or that the plugin has had limited exposure. However, this doesn't negate the immediate risks identified in the current code. The strengths lie in its clean record and SQL handling, but these are overshadowed by the identified code injection and XSS risks due to unescaped output and the use of `create_function`. The lack of any security checks on its entry points, however minimal they may be, is a significant weakness. This plugin requires immediate attention to address the identified code injection and XSS vulnerabilities to achieve a more secure state.
Key Concerns
- Dangerous function used (create_function)
- High percentage of unescaped output
- No nonce checks
- No capability checks
StatusNet Widget Security Vulnerabilities
StatusNet Widget Code Analysis
Dangerous Functions Found
Output Escaping
StatusNet Widget Attack Surface
WordPress Hooks 3
Maintenance & Trust
StatusNet Widget Maintenance & Trust
Maintenance Signals
Community Trust
StatusNet Widget Alternatives
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
StatusNet Widget Developer Profile
2 plugins · 20 total installs
How We Detect StatusNet Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/statusnet-widget/css/style.cssHTML / DOM Fingerprints
statusnetid="statusnet-widget-title"name="statusnet-widget-title"id="statusnet-widget-merged"name="statusnet-widget-merged"id="statusnet-widget-prefer_content"name="statusnet-widget-prefer_content"+6 more