Structured Social Profiles Security & Risk Analysis

wordpress.org/plugins/structured-social-profiles

This plugin adds structured data to Google search results.

40 active installs v1.0.1 PHP + WP 3.1+ Updated Jan 30, 2015
googlesocialsocial-profilesstructured-data
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Structured Social Profiles Safe to Use in 2026?

Generally Safe

Score 85/100

Structured Social Profiles has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "structured-social-profiles" plugin version 1.0.1 exhibits a strong security posture based on the provided static analysis. The absence of any identifiable attack surface, such as AJAX handlers, REST API routes, shortcodes, or cron events, significantly reduces the potential for external exploitation. Furthermore, the code demonstrates good practices by exclusively using prepared statements for its SQL queries and avoiding dangerous functions, file operations, and external HTTP requests. The lack of any recorded vulnerabilities, including CVEs, further reinforces this positive assessment.

However, a significant concern arises from the output escaping analysis, where only 10% of the 20 total outputs are properly escaped. This indicates a considerable risk of Cross-Site Scripting (XSS) vulnerabilities. While the plugin has no known vulnerability history, this lack of proper output sanitization could allow an attacker to inject malicious scripts into the site, impacting users who view the profile data. The absence of nonce and capability checks on any potential entry points, though the current analysis shows zero entry points, means that if any were introduced in future updates without proper checks, they could be exploited.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Structured Social Profiles Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Structured Social Profiles Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

10% escaped20 total outputs
Attack Surface

Structured Social Profiles Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initclass-admin.php:9
actionadmin_menuclass-admin.php:31
actionwp_headclass-frontend.php:57
Maintenance & Trust

Structured Social Profiles Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedJan 30, 2015
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings3
Active installs40
Developer Profile

Structured Social Profiles Developer Profile

Alex Moss

11 plugins · 4K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
249 days
View full developer profile
Detection Fingerprints

How We Detect Structured Social Profiles

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/structured-social-profiles/style.css
Version Parameters
structured-social-profiles/style.css?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Structured Social Profiles Plugin for WordPress: http://peadig.com/wordpress-plugins/structured-social-profiles/ -->
FAQ

Frequently Asked Questions about Structured Social Profiles