
WP Social-link Security & Risk Analysis
wordpress.org/plugins/wp-social-linkWP Social-link is beautifully designed and elegant plugin.Very easy to use and perfect functionality. WP Social-link is best Social-link plugin in Wor …
Is WP Social-link Safe to Use in 2026?
Generally Safe
Score 85/100WP Social-link has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-social-link" v1.0 plugin presents a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and utilizes prepared statements for all SQL queries, which is a strong practice against SQL injection. There are no dangerous functions, file operations, external HTTP requests, or bundled libraries to indicate known risks in those areas. The taint analysis also shows no critical or high-severity flows, suggesting a lack of obvious data manipulation vulnerabilities.
However, there are significant concerns. The plugin exhibits a complete lack of output escaping for all 21 detected output points. This is a critical weakness that opens the door to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site's pages. Furthermore, the absence of nonce and capability checks on its single shortcode, which is an entry point, means that any user, regardless of their role or privilege, could potentially trigger unintended actions if the shortcode has any underlying functionality that modifies data or performs actions. This combination of unescaped output and insufficient authorization checks represents a notable security risk.
While the plugin's vulnerability history is clean, this could be due to its limited version or lack of extensive security auditing. The current static analysis reveals critical oversights in output escaping and authorization that need immediate attention. It is crucial to address the XSS and potential authorization bypass vulnerabilities stemming from the unescaped outputs and the unprotected shortcode to secure the plugin effectively.
Key Concerns
- All outputs are unescaped
- Shortcode lacks nonce/capability checks
WP Social-link Security Vulnerabilities
WP Social-link Code Analysis
Output Escaping
WP Social-link Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
WP Social-link Maintenance & Trust
Maintenance Signals
Community Trust
WP Social-link Alternatives
No alternatives data available yet.
WP Social-link Developer Profile
10 plugins · 190 total installs
How We Detect WP Social-link
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-social-link/css/bootstrap.css/wp-content/plugins/wp-social-link/css/fonts.css/wp-content/plugins/wp-social-link/style.css/wp-content/plugins/wp-social-link/js/bootstrap.jsHTML / DOM Fingerprints
social-infosocialsocial-info pull-rightdata-cfemailwp_social_link_options<header id="header"><div class="social-info pull-right "><ul class="social textcolor list-unstyled">