WP Social-link Security & Risk Analysis

wordpress.org/plugins/wp-social-link

WP Social-link is beautifully designed and elegant plugin.Very easy to use and perfect functionality. WP Social-link is best Social-link plugin in Wor …

10 active installs v1.0 PHP + WP 3.0.1+ Updated Dec 12, 2016
awesome-social-linkbootstrap-social-linklink-social-linkshare-social-link
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Social-link Safe to Use in 2026?

Generally Safe

Score 85/100

WP Social-link has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "wp-social-link" v1.0 plugin presents a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and utilizes prepared statements for all SQL queries, which is a strong practice against SQL injection. There are no dangerous functions, file operations, external HTTP requests, or bundled libraries to indicate known risks in those areas. The taint analysis also shows no critical or high-severity flows, suggesting a lack of obvious data manipulation vulnerabilities.

However, there are significant concerns. The plugin exhibits a complete lack of output escaping for all 21 detected output points. This is a critical weakness that opens the door to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site's pages. Furthermore, the absence of nonce and capability checks on its single shortcode, which is an entry point, means that any user, regardless of their role or privilege, could potentially trigger unintended actions if the shortcode has any underlying functionality that modifies data or performs actions. This combination of unescaped output and insufficient authorization checks represents a notable security risk.

While the plugin's vulnerability history is clean, this could be due to its limited version or lack of extensive security auditing. The current static analysis reveals critical oversights in output escaping and authorization that need immediate attention. It is crucial to address the XSS and potential authorization bypass vulnerabilities stemming from the unescaped outputs and the unprotected shortcode to secure the plugin effectively.

Key Concerns

  • All outputs are unescaped
  • Shortcode lacks nonce/capability checks
Vulnerabilities
None known

WP Social-link Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP Social-link Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped21 total outputs
Attack Surface

WP Social-link Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[social_link] main-functions.php:73
WordPress Hooks 7
actioninitmain-functions.php:17
actioninitmain-functions.php:28
actionadmin_menumain-functions.php:80
actionadmin_enqueue_scriptsmain-functions.php:83
actionadmin_initmain-functions.php:109
actionwp_headmain-functions.php:302
filterwidget_textmain-functions.php:305
Maintenance & Trust

WP Social-link Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedDec 12, 2016
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

WP Social-link Alternatives

No alternatives data available yet.

Developer Profile

WP Social-link Developer Profile

Sohelwpexpert

10 plugins · 190 total installs

78
trust score
Avg Security Score
86/100
Avg Patch Time
50 days
View full developer profile
Detection Fingerprints

How We Detect WP Social-link

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-social-link/css/bootstrap.css/wp-content/plugins/wp-social-link/css/fonts.css/wp-content/plugins/wp-social-link/style.css
Script Paths
/wp-content/plugins/wp-social-link/js/bootstrap.js

HTML / DOM Fingerprints

CSS Classes
social-infosocialsocial-info pull-right
Data Attributes
data-cfemail
JS Globals
wp_social_link_options
Shortcode Output
<header id="header"><div class="social-info pull-right "><ul class="social textcolor list-unstyled">
FAQ

Frequently Asked Questions about WP Social-link