User Social Profiles Security & Risk Analysis

wordpress.org/plugins/user-social-profiles

Plugin adds social fields to user profile in admin panel (Dashboard > Users).

200 active installs v0.1.5 PHP + WP 4.0+ Updated Dec 11, 2018
social-accountssocial-profilessocial-user-fieldsuser-social-profiles
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is User Social Profiles Safe to Use in 2026?

Generally Safe

Score 85/100

User Social Profiles has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'user-social-profiles' plugin v0.1.5 currently exhibits a strong security posture. The static analysis reveals no identified attack surface points such as AJAX handlers, REST API routes, shortcodes, or cron events that are accessible to unauthorized users. Furthermore, the code signals indicate robust security practices, with no dangerous functions, all SQL queries utilizing prepared statements, and all output properly escaped. There are also no file operations, external HTTP requests, nonce checks, or capability checks detected, suggesting a minimal and potentially over-sanitized codebase in terms of interaction points.

The taint analysis also yields no concerning findings, with zero flows analyzed or flows with unsanitized paths, indicating no apparent vulnerabilities related to data manipulation or injection. The vulnerability history is equally positive, showing no known CVEs, unpatched vulnerabilities, or a history of common vulnerability types. This suggests the plugin has either been very secure historically or has not been subjected to extensive security auditing or real-world exploitation.

While the absence of identified vulnerabilities and a clean static analysis are positive indicators, the near-zero attack surface and lack of certain security mechanisms like capability checks or nonce checks on potential interaction points (if they existed) could also indicate a very limited functionality or an incomplete analysis. However, given the data, the plugin appears to be exceptionally secure. The primary strength is the absence of any detected security flaws. A potential weakness, though not directly a security flaw based on the data, is the lack of explicit security checks like capability checks, which might be a concern if the plugin's functionality were to expand in the future without proper security implementations. Overall, for its current reported state, the plugin presents a very low risk.

Vulnerabilities
None known

User Social Profiles Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

User Social Profiles Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

User Social Profiles Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filteruser_contactmethodsuser-social-profiles.php:33
Maintenance & Trust

User Social Profiles Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedDec 11, 2018
PHP min version
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

User Social Profiles Developer Profile

Patryk Kachel

8 plugins · 1K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect User Social Profiles

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
user-social-profiles/style.css?ver=user-social-profiles/script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about User Social Profiles