wp max social widget Security & Risk Analysis

wordpress.org/plugins/wp-max-social-widget

WP Max Social Wigdet : wordpress Social widget having most of the social icon and social bookmarking option .Wp max social widget reside on the sideba …

20 active installs v1.3.2 PHP + WP 3.0+ Updated Jan 22, 2013
facebookmax-socialsocial-bookmarksocial-widgetwordpress-max-social-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is wp max social widget Safe to Use in 2026?

Generally Safe

Score 85/100

wp max social widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The static analysis of "wp-max-social-widget" v1.3.2 reveals a plugin with a seemingly small attack surface, featuring zero identified AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed. This suggests a minimal number of direct entry points for external interaction. However, the code analysis also highlights significant security concerns. The presence of the `create_function` is a direct indicator of potential code injection vulnerabilities, especially in conjunction with the complete lack of output escaping. This means any user-controlled input that is displayed by the plugin could be manipulated to execute arbitrary code or display malicious content.

The plugin's vulnerability history is clean, with no known CVEs. This is a positive sign, indicating that the plugin has historically been free of publicly disclosed security flaws. However, the lack of past vulnerabilities does not negate the present code-level risks. The complete absence of taint analysis results is also notable; while this could mean no high-severity flows were detected, it might also be an artifact of the analysis tools or limitations in the scope of the analysis performed, especially given the significant output escaping issues.

In conclusion, while "wp-max-social-widget" v1.3.2 presents a low direct attack surface and a clean vulnerability history, the critical code quality issues, particularly the use of `create_function` and the complete lack of output escaping, introduce a substantial risk of code injection and cross-site scripting (XSS) vulnerabilities. These code-level weaknesses outweigh the apparent strengths of its limited attack surface and clean history.

Key Concerns

  • Uses dangerous function create_function
  • 0% properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

wp max social widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

wp max social widget Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
205
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('widgets_init', create_function('', 'return register_widget(\'maxsocial\');'));wp-max-social-widget.php:677

Output Escaping

0% escaped205 total outputs
Attack Surface

wp max social widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_headwp-max-social-widget.php:619
actionwp_dashboard_setupwp-max-social-widget.php:624
actionwidgets_initwp-max-social-widget.php:677
actionwp_headwp-max-social-widget.php:679
Maintenance & Trust

wp max social widget Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedJan 22, 2013
PHP min version
Downloads12K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

wp max social widget Developer Profile

Ramandeep Singh

3 plugins · 70 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect wp max social widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-max-social-widget/wp-max-social-style.css

HTML / DOM Fingerprints

CSS Classes
wp-max-social-titlemax-social-layoutmax-email-boxmax-social-media
HTML Comments
Stat of The Wp-max Social Widgethttp://www.designaeon.com/wp-max-social-widget
Data Attributes
data-sizedata-widthdata-heightdata-hrefdata-layoutdata-colorscheme+12 more
JS Globals
gapi
FAQ

Frequently Asked Questions about wp max social widget