
WeLovez Social Login For WoWonder Php Social Script Security & Risk Analysis
wordpress.org/plugins/welovez-social-loginWeLovez Social Login For WoWonder Php Social Script a free powerful WordPress plugin that will allow wowonder (your social media) users to login to an …
Is WeLovez Social Login For WoWonder Php Social Script Safe to Use in 2026?
Generally Safe
Score 85/100WeLovez Social Login For WoWonder Php Social Script has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The welovez-social-login plugin version 2.1 exhibits a generally good security posture, with no reported vulnerabilities or critical issues identified in the static and taint analysis. The plugin demonstrates strong practices by using prepared statements for all SQL queries and having a limited attack surface with all entry points protected by authentication. The absence of file operations and dangerous functions further contributes to its security.
However, there are areas for improvement. The low percentage of properly escaped output (29%) is a significant concern. This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied data may be directly rendered in the browser without sufficient sanitization. While the plugin has only two external HTTP requests, the nature of these requests is not detailed, which could represent a potential risk if not handled securely. The presence of only one nonce check for three entry points is also a weakness, particularly if some of the AJAX handlers are not adequately protected.
Overall, while the plugin benefits from a clean vulnerability history and a well-protected primary attack surface, the insufficient output escaping presents a tangible risk of XSS. Addressing this would significantly improve the plugin's security.
Key Concerns
- Low output escaping percentage
- Potential for XSS in unescaped output
- Insufficient nonce checks for entry points
WeLovez Social Login For WoWonder Php Social Script Security Vulnerabilities
WeLovez Social Login For WoWonder Php Social Script Code Analysis
Output Escaping
WeLovez Social Login For WoWonder Php Social Script Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 5
Maintenance & Trust
WeLovez Social Login For WoWonder Php Social Script Maintenance & Trust
Maintenance Signals
Community Trust
WeLovez Social Login For WoWonder Php Social Script Alternatives
Wp Social Login and Register Social Counter
wp-social
Wp social lets you add social login, social counter, and social share buttons of different styles to your WordPress website.
Social Share, Social Login and Social Comments Plugin – Super Socializer
super-socializer
The unique Social Plugin to let you integrate Social Login, Social Share, Social Comments and Social Media follow at your website
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
WeLovez Social Login For WoWonder Php Social Script Developer Profile
1 plugin · 10 total installs
How We Detect WeLovez Social Login For WoWonder Php Social Script
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/welovez-social-login/assets/images/button-wrapper.png/wp-content/plugins/welovez-social-login/assets/images/welovez.pngHTML / DOM Fingerprints
welovez-sharewelovez-wrapperwelovez-buttonid="welovez-wrapper"id="welovez-button"class="welovez-share"<div id="welovez-wrapper"><a href="class="btn" id="welovez-button"><div class="content-share__item lovez buzz-share-button">