
Open Graph and Twitter Card Tags Security & Risk Analysis
wordpress.org/plugins/wonderm00ns-simple-facebook-open-graph-tagsImprove social media sharing by inserting Facebook Open Graph, Twitter Card, and SEO Meta Tags on your WordPress website pages, posts, WooCommerce pro …
Is Open Graph and Twitter Card Tags Safe to Use in 2026?
Generally Safe
Score 99/100Open Graph and Twitter Card Tags has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "wonderm00ns-simple-facebook-open-graph-tags" plugin v3.3.9 demonstrates generally good security practices, with a low attack surface and a high percentage of properly escaped outputs and prepared SQL statements. The plugin also incorporates a good number of nonce and capability checks. However, the presence of two past medium-severity Cross-Site Scripting (XSS) vulnerabilities, both last patched in 2018, suggests a history of input sanitization issues. While there are no currently unpatched CVEs, this historical pattern warrants caution. The taint analysis did reveal three flows with unsanitized paths, which, although not classified as critical or high severity in this analysis, could potentially lead to security issues if not handled with extreme care in future versions or if combined with other factors. The plugin's limited file operations and external HTTP requests are positive indicators. The overall security posture is moderately strong, with a good foundation of secure coding practices, but the historical XSS vulnerabilities and the identified unsanitized taint flows present an area for continued vigilance and potential improvement.
Key Concerns
- Past medium severity XSS vulnerabilities
- Flows with unsanitized paths identified
Open Graph and Twitter Card Tags Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Open Graph and Twitter Card Tags <= 2.2.4.1 - Unauthenticated Cross-Site Scripting
Open Graph and Twitter Card Tags < 2.2.4.1 - Reflected Cross-Site Scripting
Open Graph and Twitter Card Tags Release Timeline
Open Graph and Twitter Card Tags Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Open Graph and Twitter Card Tags Attack Surface
AJAX Handlers 2
REST API Routes 1
WordPress Hooks 32
Maintenance & Trust
Open Graph and Twitter Card Tags Maintenance & Trust
Maintenance Signals
Community Trust
Open Graph and Twitter Card Tags Alternatives
Social Media Card Generator
social-media-card-generator
Short Description: A WordPress plugin to easily generate custom social media cards for posts.
OG — Better Share on Social Media
og
The simple method to add Open Graph metadata to your entries so that they look great when shared on sites.
Optimize Social Share
heateor-open-graph-meta-tags
Optimizes social share by inserting Facebook Open Graph Meta Tags, General Meta Tags, Schema.org Meta Tags, Twitter Cards and Other Meta Tags in HTML …
Open Graph Protocol Framework
open-graph-protocol-framework
The Open Graph Protocol enables any web page to become a rich object in a social graph. This plugin renders meta tags within an extension framework.
Open Graph Pro
ogp
Adds Open Graph tags to your blog. Control how your posts and pages are presented on Facebook and other social media sites. No configuration needed.
Open Graph and Twitter Card Tags Developer Profile
89 plugins · 1.4M total installs
How We Detect Open Graph and Twitter Card Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wonderm00ns-simple-facebook-open-graph-tags/admin/css/style.css/wp-content/plugins/wonderm00ns-simple-facebook-open-graph-tags/admin/js/script.js/wp-content/plugins/wonderm00ns-simple-facebook-open-graph-tags/admin/js/script.jswonderm00ns-simple-facebook-open-graph-tags/admin/css/style.css?ver=wonderm00ns-simple-facebook-open-graph-tags/admin/js/script.js?ver=HTML / DOM Fingerprints
ogatc-settings