WPSN: Instant Social Network Security & Risk Analysis

wordpress.org/plugins/wpsn-instant-social-network

Instantly and easily turn your website into a social network! Profile, Posts, Photos, Videos, Friends, Alerts - and more!

0 active installs v0.8.7 PHP 7.0+ WP 6.5.3+ Updated Sep 28, 2024
communityforumgroupssocial-mediasocial-network
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPSN: Instant Social Network Safe to Use in 2026?

Generally Safe

Score 92/100

WPSN: Instant Social Network has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The wpsn-instant-social-network v0.8.7 plugin exhibits a generally good security posture, with several positive indicators. The absence of any recorded vulnerabilities (CVEs) and the meticulous use of prepared statements for all SQL queries are significant strengths. Furthermore, the high percentage of properly escaped output and the presence of nonce checks on a majority of entry points suggest a developer mindful of common web security pitfalls. The plugin also shows no direct external HTTP requests, which reduces the attack surface related to third-party integrations.

However, a few areas warrant attention. The static analysis reveals the presence of four 'dangerous functions', specifically `unserialize`. While the taint analysis did not reveal any exploitable flows related to this, improper sanitization of data that is later unserialized can lead to Remote Code Execution (RCE) or other serious vulnerabilities. The plugin also performs file operations, and without thorough validation of user-supplied file paths, this could potentially lead to directory traversal or arbitrary file read/write vulnerabilities. The capability checks are also quite low (only 2), which could indicate a potential for privilege escalation if not all entry points are properly secured by WordPress's built-in role and capability system, although the report states 0 unprotected entry points.

Overall, wpsn-instant-social-network v0.8.7 appears to be a relatively secure plugin, primarily due to its lack of historical vulnerabilities and good practices in database interaction and output sanitization. The main area of concern lies in the potential risks associated with the use of `unserialize` and file operations, which, while not currently exploited according to the analysis, could represent latent vulnerabilities if not handled with extreme care and robust input validation. Continued vigilance and potential further review of the `unserialize` and file operation implementations would be prudent.

Key Concerns

  • Use of 'unserialize' function
  • Presence of file operations
  • Low number of capability checks
Vulnerabilities
None known

WPSN: Instant Social Network Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WPSN: Instant Social Network Code Analysis

Dangerous Functions
4
Raw SQL Queries
0
0 prepared
Unescaped Output
31
582 escaped
Nonce Checks
39
Capability Checks
2
File Operations
8
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$images = unserialize($attachments);ajax\wpsn_story_ajax.php:83
unserialize$images = unserialize($attachments);ajax\wpsn_story_ajax.php:669
unserialize$images = unserialize($attachments);ajax\wpsn_story_ajax.php:724
unserialize$images = unserialize($attachments);ajax\wpsn_story_ajax.php:1320

Output Escaping

95% escaped613 total outputs
Data Flows
All sanitized

Data Flow Analysis

14 flows
wpsn_add_page (ajax\wpsn_admin_ajax.php:3)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WPSN: Instant Social Network Attack Surface

Entry Points42
Unprotected0

AJAX Handlers 34

authwp_ajax_wpsn_add_pageajax\wpsn_admin_ajax.php:37
authwp_ajax_wpsn_admin_email_sendajax\wpsn_admin_ajax.php:83
authwp_ajax_wpsn_save_emailajax\wpsn_admin_ajax.php:114
authwp_ajax_wpsn_save_pagesajax\wpsn_admin_ajax.php:174
authwp_ajax_wpsn_save_customizeajax\wpsn_admin_ajax.php:301
authwp_ajax_wpsn_save_activityajax\wpsn_admin_ajax.php:344
authwp_ajax_wpsn_theme_alertsajax\wpsn_alerts_ajax.php:66
authwp_ajax_wpsn_get_alertsajax\wpsn_alerts_ajax.php:236
authwp_ajax_wpsn_clear_alertsajax\wpsn_alerts_ajax.php:288
authwp_ajax_wpsn_theme_friendsajax\wpsn_friends_ajax.php:53
authwp_ajax_wpsn_cancel_friend_removeajax\wpsn_friends_ajax.php:126
authwp_ajax_wpsn_friend_accept_receivedajax\wpsn_friends_ajax.php:291
authwp_ajax_wpsn_cancel_friend_request_receivedajax\wpsn_friends_ajax.php:363
authwp_ajax_wpsn_cancel_friend_requestajax\wpsn_friends_ajax.php:442
authwp_ajax_wpsn_add_friend_requestajax\wpsn_friends_ajax.php:567
authwp_ajax_wpsn_get_friendsajax\wpsn_friends_ajax.php:700
authwp_ajax_wpsn_side_bar_friendsajax\wpsn_friends_ajax.php:776
authwp_ajax_wpsn_logoutajax\wpsn_login_ajax.php:28
noprivwp_ajax_wpsn_logoutajax\wpsn_login_ajax.php:29
noprivwp_ajax_wpsn_new_passwordajax\wpsn_login_ajax.php:96
authwp_ajax_wpsn_validate_loginajax\wpsn_login_ajax.php:156
noprivwp_ajax_wpsn_validate_loginajax\wpsn_login_ajax.php:157
noprivwp_ajax_wpsn_sign_up_userajax\wpsn_login_ajax.php:206
authwp_ajax_wpsn_save_profile_detailsajax\wpsn_profile_ajax.php:97
authwp_ajax_wpsn_do_searchajax\wpsn_search_ajax.php:91
authwp_ajax_wpsn_get_user_statusajax\wpsn_story_ajax.php:35
authwp_ajax_wpsn_side_bar_photosajax\wpsn_story_ajax.php:121
authwp_ajax_wpsn_insert_feed_postajax\wpsn_story_ajax.php:606
authwp_ajax_wpsn_delete_postajax\wpsn_story_ajax.php:655
authwp_ajax_wpsn_get_post_imagesajax\wpsn_story_ajax.php:702
authwp_ajax_wpsn_get_post_infoajax\wpsn_story_ajax.php:753
authwp_ajax_wpsn_get_postsajax\wpsn_story_ajax.php:851
authwp_ajax_wpsn_save_avataredit_profile.php:226
authwp_ajax_wpsn_save_coveredit_profile.php:296

Shortcodes 8

[wpsn-home] wpsn-instant-social-network.php:244
[wpsn-activity] wpsn-instant-social-network.php:246
[wpsn-friends] wpsn-instant-social-network.php:248
[wpsn-profile-edit] wpsn-instant-social-network.php:250
[wpsn-alerts] wpsn-instant-social-network.php:252
[wpsn-search] wpsn-instant-social-network.php:254
[wpsn-login] wpsn-instant-social-network.php:256
[wpsn-signup] wpsn-instant-social-network.php:257
WordPress Hooks 25
actionplugins_loadedfunctions.php:25
actionadmin_initfunctions.php:446
actioninitwpsn-instant-social-network.php:22
actionwp_loginwpsn-instant-social-network.php:51
actionadmin_enqueue_scriptswpsn-instant-social-network.php:52
actionwp_enqueue_scriptswpsn-instant-social-network.php:53
actioninitwpsn-instant-social-network.php:54
actioninitwpsn-instant-social-network.php:55
actioninitwpsn-instant-social-network.php:56
actioninitwpsn-instant-social-network.php:57
actionwp_headwpsn-instant-social-network.php:58
actiontemplate_redirectwpsn-instant-social-network.php:60
filtercron_scheduleswpsn-instant-social-network.php:94
actionwpsn_custom_cron_jobwpsn-instant-social-network.php:131
actionadmin_menuwpsn-instant-social-network.php:222
actionadmin_enqueue_scriptswpsn-instant-social-network.php:224
actionadmin_enqueue_scriptswpsn-instant-social-network.php:226
actionadmin_enqueue_scriptswpsn-instant-social-network.php:228
filtermanage_wpsn-email_posts_columnswpsn-instant-social-network.php:232
actionmanage_wpsn-email_posts_custom_columnwpsn-instant-social-network.php:233
actionmanage_posts_extra_tablenavwpsn-instant-social-network.php:234
actiontemplate_redirectwpsn-instant-social-network.php:238
actiontemplate_redirectwpsn-instant-social-network.php:239
actionwp_headwpsn-instant-social-network.php:241
actionwp_headwpsn-instant-social-network.php:242

Scheduled Events 2

wpsn_custom_cron_job
wpsn_custom_cron_job
Maintenance & Trust

WPSN: Instant Social Network Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 28, 2024
PHP min version7.0
Downloads837

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WPSN: Instant Social Network Developer Profile

Simon Goodchild

2 plugins · 10 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPSN: Instant Social Network

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpsn-instant-social-network/js/wpsn_custom.js/wp-content/plugins/wpsn-instant-social-network/css/wpsn_custom.css/wp-content/plugins/wpsn-instant-social-network/js/wpsn_scripts.js/wp-content/plugins/wpsn-instant-social-network/assets/css/vendors/materialize.min.css/wp-content/plugins/wpsn-instant-social-network/assets/js/vendors/materialize.min.js/wp-content/plugins/wpsn-instant-social-network/assets/js/wpsn_social.js
Script Paths
/wp-content/plugins/wpsn-instant-social-network/js/wpsn_custom.js/wp-content/plugins/wpsn-instant-social-network/js/wpsn_scripts.js/wp-content/plugins/wpsn-instant-social-network/assets/js/vendors/materialize.min.js/wp-content/plugins/wpsn-instant-social-network/assets/js/wpsn_social.js
Version Parameters
wpsn-instant-social-network/js/wpsn_custom.js?ver=wpsn-instant-social-network/css/wpsn_custom.css?ver=wpsn-instant-social-network/js/wpsn_scripts.js?ver=wpsn-instant-social-network/assets/css/vendors/materialize.min.css?ver=wpsn-instant-social-network/assets/js/vendors/materialize.min.js?ver=wpsn-instant-social-network/assets/js/wpsn_social.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpsn_user_dashboardwpsn-story-container
HTML Comments
<!-- WPSN: Social Network for WordPress Plugin --><!-- END WPSN --><!-- WPSN: instant Social Network Admin Menu --><!-- ADD WPSN Menu -->+12 more
Data Attributes
data-wpsn-user-id
JS Globals
WPSN_AJAX_URL
FAQ

Frequently Asked Questions about WPSN: Instant Social Network