
WP30 By Who Security & Risk Analysis
wordpress.org/plugins/wp30-by-who"WP30 By Who" is a simple add-on that enable a small bar for label "Designed by" and social media icons links at the bottom.
Is WP30 By Who Safe to Use in 2026?
Generally Safe
Score 85/100WP30 By Who has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wp30-by-who" v1.0.0 exhibits a very strong security posture based on the provided static analysis and vulnerability history. The absence of any identified entry points, dangerous functions, raw SQL queries, file operations, external HTTP requests, or taint flows suggests a meticulously crafted codebase that adheres to best security practices. Furthermore, the lack of any known vulnerabilities in its history reinforces this positive outlook, indicating a well-maintained and secure plugin.
However, a critical area of concern is the significantly low percentage of properly escaped output (21%). This indicates a high risk of cross-site scripting (XSS) vulnerabilities. While the static analysis did not detect specific XSS flows, the sheer volume of unescaped output presents a substantial attack surface for privilege escalation and user data compromise. The absence of nonce and capability checks, while not directly flagged as critical in this instance due to the lack of exposed entry points, represents a missed opportunity for robust authorization, which could become a weakness if the plugin's attack surface were to expand in future versions.
In conclusion, the plugin demonstrates excellent security by avoiding common pitfalls like raw SQL and external requests. The primary weakness lies in the inadequate output escaping, which requires immediate attention. The clean vulnerability history is a significant strength, but it should not overshadow the critical need to address the output sanitization issues.
Key Concerns
- Low percentage of properly escaped output
WP30 By Who Security Vulnerabilities
WP30 By Who Code Analysis
Output Escaping
WP30 By Who Attack Surface
WordPress Hooks 10
Maintenance & Trust
WP30 By Who Maintenance & Trust
Maintenance Signals
Community Trust
WP30 By Who Alternatives
Social Media Widget
social-media-widgets
Easily create beautiful social media link with the install of this plugin.This widget takes a simple, extendable approach for displaying your social m …
Social Space
social-space
A ridiculously simple plugin for showing your social network links using a simple widget so that people can connect with you more easily.
Social Toolbar
social-toolbar
Plugin for adding a highly customizable toolbar with color selection, social network icons, recent tweet and share buttons into footer.
Don Social Widget
don-social-widget
Just another social widget plugin, put it in your sidebars and footer. Simple and flat.
TF Button
tf-button
Add the new Twitter Follow Button to your website to increase engagement and create a lasting connection with your audience.
WP30 By Who Developer Profile
8 plugins · 1K total installs
How We Detect WP30 By Who
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp30-by-who/css/wp30-by-who-admin.css/wp-content/plugins/wp30-by-who/js/wp30-by-who-admin.js/wp-content/plugins/wp30-by-who/js/wp30-by-who-admin.jswp30-by-who/css/wp30-by-who-admin.css?ver=wp30-by-who/js/wp30-by-who-admin.js?ver=