
Social Preview and Open Graph Tags Security & Risk Analysis
wordpress.org/plugins/wonderm00ns-simple-facebook-open-graph-tagsControl how your WordPress posts, pages, WooCommerce products, and custom post types look when shared on Facebook, X/Twitter, LinkedIn, WhatsApp, Slac …
Is Social Preview and Open Graph Tags Safe to Use in 2026?
Generally Safe
Score 99/100Social Preview and Open Graph Tags has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "wonderm00ns-simple-facebook-open-graph-tags" plugin v3.3.9 demonstrates generally good security practices, with a low attack surface and a high percentage of properly escaped outputs and prepared SQL statements. The plugin also incorporates a good number of nonce and capability checks. However, the presence of two past medium-severity Cross-Site Scripting (XSS) vulnerabilities, both last patched in 2018, suggests a history of input sanitization issues. While there are no currently unpatched CVEs, this historical pattern warrants caution. The taint analysis did reveal three flows with unsanitized paths, which, although not classified as critical or high severity in this analysis, could potentially lead to security issues if not handled with extreme care in future versions or if combined with other factors. The plugin's limited file operations and external HTTP requests are positive indicators. The overall security posture is moderately strong, with a good foundation of secure coding practices, but the historical XSS vulnerabilities and the identified unsanitized taint flows present an area for continued vigilance and potential improvement.
Key Concerns
- Past medium severity XSS vulnerabilities
- Flows with unsanitized paths identified
Social Preview and Open Graph Tags Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Open Graph and Twitter Card Tags <= 2.2.4.1 - Unauthenticated Cross-Site Scripting
Open Graph and Twitter Card Tags < 2.2.4.1 - Reflected Cross-Site Scripting
Social Preview and Open Graph Tags Release Timeline
Social Preview and Open Graph Tags Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Social Preview and Open Graph Tags Attack Surface
AJAX Handlers 2
REST API Routes 1
WordPress Hooks 32
Maintenance & Trust
Social Preview and Open Graph Tags Maintenance & Trust
Maintenance Signals
Community Trust
Social Preview and Open Graph Tags Alternatives
Optimize Social Share
heateor-open-graph-meta-tags
Optimizes social share by inserting Facebook Open Graph Meta Tags, General Meta Tags, Schema.org Meta Tags, Twitter Cards and Other Meta Tags in HTML …
OG Pilot Dynamic Open Graph Images
og-pilot-dynamic-open-graph-images
Dynamic Open Graph images and X/Twitter cards for WordPress and WooCommerce. Auto-generate social preview images for posts, pages, and products.
MightyShare – Auto-Generated Social Media Images
mightyshare
Automatically generate social share preview images with MightyShare!
Unfurl – One Click To Post
unfurl-one-click-to-post
Make new post from a link in one click, like on Twitter
WP Social Integration
wp-social-integration
WP social integration brings login by facebook, adds basic & opengraph metadata, facebook social plugins anywhere in page
Social Preview and Open Graph Tags Developer Profile
89 plugins · 1.3M total installs
How We Detect Social Preview and Open Graph Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wonderm00ns-simple-facebook-open-graph-tags/admin/css/style.css/wp-content/plugins/wonderm00ns-simple-facebook-open-graph-tags/admin/js/script.js/wp-content/plugins/wonderm00ns-simple-facebook-open-graph-tags/admin/js/script.jswonderm00ns-simple-facebook-open-graph-tags/admin/css/style.css?ver=wonderm00ns-simple-facebook-open-graph-tags/admin/js/script.js?ver=HTML / DOM Fingerprints
ogatc-settings