Social Meta by Brozzme Security & Risk Analysis

wordpress.org/plugins/wp-social-meta-by-brozzme

Add social meta for pages in header without coding.

30 active installs v1.0 PHP + WP 4.5+ Updated Oct 28, 2021
facebookheadermetaopengraphsocial
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Meta by Brozzme Safe to Use in 2026?

Generally Safe

Score 85/100

Social Meta by Brozzme has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "wp-social-meta-by-brozzme" v1.0 plugin exhibits a mixed security posture. On one hand, the static analysis reveals a remarkably clean attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events directly exposed or unprotected. Furthermore, the plugin demonstrates good practice by using prepared statements for all its SQL queries and reports no file operations or external HTTP requests, which are common vectors for vulnerabilities.

However, a significant concern arises from the output escaping. With only 32% of outputs properly escaped out of 57 total, there is a high probability of Cross-Site Scripting (XSS) vulnerabilities. The lack of capability checks and nonce checks also suggests that any potential vulnerabilities discovered could be exploited without proper authorization or validation, especially if there were entry points. The absence of any recorded vulnerabilities in its history, while positive, could also indicate a lack of rigorous security testing or that the plugin hasn't been targeted historically, rather than an inherent security strength.

In conclusion, while the plugin avoids common pitfalls like raw SQL and a large attack surface, the widespread issue with output escaping presents a substantial risk for XSS. The absence of robust authorization checks further exacerbates this potential risk. Without addressing the output escaping, the plugin remains vulnerable.

Key Concerns

  • Low percentage of properly escaped output
  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

Social Meta by Brozzme Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Social Meta by Brozzme Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
39
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

32% escaped57 total outputs
Attack Surface

Social Meta by Brozzme Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_initincludes\wpsmb_options.php:9
actionadmin_menuwp-social-meta-brozzme.php:120
actionplugins_loadedwp-social-meta-brozzme.php:128
actionadmin_print_scriptswp-social-meta-brozzme.php:158
actionadmin_print_styleswp-social-meta-brozzme.php:159
filterlanguage_attributeswp-social-meta-brozzme.php:182
actionwp_headwp-social-meta-brozzme.php:185
actioninitwp-social-meta-brozzme.php:444
actionwp_headwp-social-meta-brozzme.php:460
Maintenance & Trust

Social Meta by Brozzme Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedOct 28, 2021
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings3
Active installs30
Developer Profile

Social Meta by Brozzme Developer Profile

Benoti

11 plugins · 11K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Social Meta by Brozzme

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-social-meta-by-brozzme/js/wpsmb-media_upload.js
Script Paths
/wp-content/plugins/wp-social-meta-by-brozzme/js/wpsmb-media_upload.js
Version Parameters
wp-social-meta-by-brozzme/js/wpsmb-media_upload.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Social Meta by Brozzme