Wp Fixed Social Profile Icons Security & Risk Analysis

wordpress.org/plugins/wp-fixed-social-profile-icons

Fixed Social Icons for your wordpress website

80 active installs v1.1 PHP + WP 3.5+ Updated Nov 8, 2023
facebookgoogle-plusinstagramsocialtwitter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wp Fixed Social Profile Icons Safe to Use in 2026?

Generally Safe

Score 85/100

Wp Fixed Social Profile Icons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "wp-fixed-social-profile-icons" v1.1 plugin exhibits a concerning security posture primarily due to a complete lack of output escaping, despite having no identified vulnerabilities in its history and employing prepared statements for any potential SQL interactions. While the absence of known CVEs and a small attack surface (zero entry points) are positive indicators, the 100% unescaped output across 13 identified outputs presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through data handled by this plugin, which would then be rendered directly in the user's browser without sanitization. The lack of capability checks and nonce checks also means that even if there were entry points, they could be exploited without proper authorization. Overall, the plugin appears to be actively maintained with no known past issues, but the critical oversight in output sanitization makes it a high-risk target for XSS attacks.

Key Concerns

  • 100% unescaped output
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

Wp Fixed Social Profile Icons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wp Fixed Social Profile Icons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped13 total outputs
Attack Surface

Wp Fixed Social Profile Icons Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menufixed-social-profile-icons.php:18
actionadmin_initfixed-social-profile-icons.php:19
actionadmin_enqueue_scriptsfixed-social-profile-icons.php:20
filterplugin_action_linksfixed-social-profile-icons.php:21
actionwp_enqueue_scriptsfixed-social-profile-icons.php:23
actionwp_footerfixed-social-profile-icons.php:24
actionwp_headfixed-social-profile-icons.php:25
Maintenance & Trust

Wp Fixed Social Profile Icons Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedNov 8, 2023
PHP min version
Downloads4K

Community Trust

Rating94/100
Number of ratings3
Active installs80
Developer Profile

Wp Fixed Social Profile Icons Developer Profile

Aman

11 plugins · 8K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
138 days
View full developer profile
Detection Fingerprints

How We Detect Wp Fixed Social Profile Icons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-fixed-social-profile-icons/fsi.css

HTML / DOM Fingerprints

CSS Classes
fsi-iconsfsi-social-icons-rightfsi-social-icons-leftfacebooki7googlei7twitteri7linkedini7youtubei7+5 more
Data Attributes
data-id="facebook"data-id="google"data-id="twitter"data-id="linkedin"data-id="youtube"data-id="tumblr"+20 more
JS Globals
window.jQueryjQuery
FAQ

Frequently Asked Questions about Wp Fixed Social Profile Icons