
Top Social Stories Free Security & Risk Analysis
wordpress.org/plugins/top-social-stories-freeCollects social data and shows you which posts are most popular based on post shares across popular social networks. With widget. Tracks data from...
Is Top Social Stories Free Safe to Use in 2026?
Generally Safe
Score 85/100Top Social Stories Free has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "top-social-stories-free" plugin version 1.83 presents significant security concerns primarily due to a lack of proper authentication checks on its AJAX handlers. With 7 AJAX handlers identified and all of them lacking authentication checks, this creates a large attack surface that is easily exploitable by unauthenticated users. Furthermore, the presence of taint analysis flows with unsanitized paths, specifically two of high severity, indicates potential for data injection or manipulation if these paths are reachable. The use of the dangerous `create_function` is another red flag, as it can lead to arbitrary code execution in certain contexts.
While the plugin has no recorded CVEs, suggesting it hasn't been publicly exploited in the past, this does not negate the immediate risks identified in the static analysis. The low percentage of properly escaped output (20%) also raises concerns about potential Cross-Site Scripting (XSS) vulnerabilities. The plugin's strengths lie in its absence of bundled libraries, a clean slate in terms of vulnerability history, and a moderate use of prepared statements for SQL queries. However, the critical findings related to unprotected AJAX endpoints, unsanitized taint flows, and the use of `create_function` heavily outweigh these positives, pointing to a plugin that requires immediate attention to secure its entry points and sanitize its data processing.
Key Concerns
- Unprotected AJAX handlers (7)
- High severity taint flows (2)
- Dangerous function: create_function
- Low percentage of output escaping (20%)
- No nonce checks on AJAX
- Low percentage of capability checks (3/7 entry points)
Top Social Stories Free Security Vulnerabilities
Top Social Stories Free Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Top Social Stories Free Attack Surface
AJAX Handlers 7
WordPress Hooks 11
Maintenance & Trust
Top Social Stories Free Maintenance & Trust
Maintenance Signals
Community Trust
Top Social Stories Free Alternatives
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
google-analytics-for-wordpress
The best free Google Analytics plugin for WordPress. See how visitors find and use your website so you can grow your business with powerful analytics.
ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)
google-analytics-dashboard-for-wp
Connects Google Analytics with your WordPress site. Displays stats to help you understand your users and site content on a whole new level!
Insert Headers And Footers
wp-headers-and-footers
Include inline javascript, stylesheets, CSS code or anything you want in Header and Footer areas of your WordPress with ease.
Independent Analytics – Google Analytics Alternative for WordPress
independent-analytics
A simple WordPress analytics plugin that is privacy-friendly, fast, and an alternative to Google Analytics.
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Top Social Stories Free Developer Profile
3 plugins · 60 total installs
How We Detect Top Social Stories Free
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/top-social-stories-free/css/style.css/wp-content/plugins/top-social-stories-free/css/style.3.8.css/wp-content/plugins/top-social-stories-free/js/top-stories.js/wp-content/plugins/top-social-stories-free/js/top-stories.jstop-social-stories-free/style.css?ver=top-social-stories-free/style.3.8.css?ver=HTML / DOM Fingerprints
top-stories-admintop_stories_params