Follow Us Badges Security & Risk Analysis

wordpress.org/plugins/wpsite-follow-us-badges

Follow Us Badges by 99 Robots showcases your Facebook, Twitter, LinkedIn. YouTube, Tumblr and other social media badges.

1K active installs v3.1.11 PHP + WP 4.5+ Updated Apr 29, 2024
badgesfacebookfollow-mefollow-usshare-badge
63
C · Use Caution
CVEs total2
Unpatched1
Last CVEApr 1, 2025
Safety Verdict

Is Follow Us Badges Safe to Use in 2026?

Use With Caution

Score 63/100

Follow Us Badges has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

2 known CVEs 1 unpatched Last CVE: Apr 1, 2025Updated 2yr ago
Risk Assessment

The plugin "wpsite-follow-us-badges" v3.1.11 presents a mixed security posture. While the static analysis shows a generally good level of output escaping and no critical taint flows, there are notable areas of concern. The lack of capability checks on any entry points is a significant weakness, meaning that potentially sensitive actions could be accessed by any user. Furthermore, all SQL queries are executed without prepared statements, which introduces a risk of SQL injection, even if not immediately apparent in the taint analysis for this specific version.

The vulnerability history reveals a pattern of medium-severity Cross-Site Scripting vulnerabilities, with one CVE remaining unpatched. This ongoing history of XSS issues, coupled with the raw SQL queries and lack of capability checks, suggests a recurring oversight in secure coding practices. While the current version appears to have addressed some previous issues and has a controlled attack surface, the historical context and the identified coding practices warrant caution. The absence of external HTTP requests and file operations is a positive indicator, but it does not mitigate the risks posed by unhandled input and historical vulnerabilities.

Key Concerns

  • Unpatched CVE (Medium)
  • SQL queries lack prepared statements
  • No capability checks on entry points
Vulnerabilities
2 published

Follow Us Badges Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-31804medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Follow Us Badges <= 3.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 1, 2025Unpatched
CVE-2024-3280medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Follow Us Badges <= 3.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpsite_follow_us_badges Shortcode

May 1, 2024 Patched in 3.1.11 (31d)
Code Analysis
Analyzed Mar 16, 2026

Follow Us Badges Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
3
431 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

99% escaped434 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
wpsite_follow_us_admin_settings (wpsite-follow-us-badges.php:1197)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Follow Us Badges Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_wpsite_save_orderwpsite-follow-us-badges.php:67

Shortcodes 1

[wpsite_follow_us_badges] wpsite-follow-us-badges.php:1506
WordPress Hooks 6
actionwidgets_initwpsite-follow-us-badges.php:55
actioninitwpsite-follow-us-badges.php:60
actioninitwpsite-follow-us-badges.php:61
actionadmin_menuwpsite-follow-us-badges.php:62
filterwidget_types_to_hide_from_legacy_widget_blockwpsite-follow-us-badges.php:71
actionwp_footerwpsite-follow-us-badges.php:1740
Maintenance & Trust

Follow Us Badges Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 29, 2024
PHP min version
Downloads85K

Community Trust

Rating96/100
Number of ratings8
Active installs1K
Developer Profile

Follow Us Badges Developer Profile

DraftPress Team

12 plugins · 613K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
1011 days
View full developer profile
Detection Fingerprints

How We Detect Follow Us Badges

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpsite-follow-us-badges/css/wpsite-follow-us-badges.css
Version Parameters
wpsite-follow-us-badges/css/wpsite-follow-us-badges.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpsite-follow-us-badges
Data Attributes
data-typedata-userdata-show-screen-namedata-countdata-layoutdata-size+2 more
JS Globals
wpsite_follow_us_badges_widget_css
Shortcode Output
[wpsite_follow_us_badges]
FAQ

Frequently Asked Questions about Follow Us Badges