xBooster Social Icons with Counter Security & Risk Analysis

wordpress.org/plugins/xbooster-social-icons-with-counter

xBooster social icons with counter is providing, icons for social network sharing and social profile links as widget, shortcode and autoplacement in c …

10 active installs v1.0 PHP + WP 3.0.1+ Updated Jan 5, 2014
social-networksocial-network-sharingsocial-networkingsocial-profilesxbooster
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is xBooster Social Icons with Counter Safe to Use in 2026?

Generally Safe

Score 85/100

xBooster Social Icons with Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The 'xbooster-social-icons-with-counter' plugin version 1.0, based on the provided static analysis and vulnerability history, presents a mixed security posture. A significant strength is the absence of known CVEs and a complete reliance on prepared statements for SQL queries, indicating good practices in database interaction. Furthermore, the total lack of REST API routes and cron events, combined with a low number of total entry points, suggests a relatively contained attack surface. However, there are concerning signals within the code analysis. The presence of two instances of `create_function` is a critical red flag, as this is a deprecated and potentially dangerous PHP function that can lead to code execution vulnerabilities if not handled with extreme care. The extremely low percentage of properly escaped output (5%) is another major concern, as it signifies a high risk of Cross-Site Scripting (XSS) vulnerabilities across numerous output points. While the plugin implements nonce checks and capability checks on some entry points (4 and 0 respectively), the lack of capability checks on AJAX handlers is a weakness that could be exploited if an attacker can trigger these handlers.

The vulnerability history shows no recorded vulnerabilities, which is a positive indicator. However, this should not be taken as a guarantee of current security, especially given the code signals like `create_function` and poor output escaping. The absence of past vulnerabilities might simply mean that these specific weaknesses have not been discovered or exploited yet. In conclusion, while the plugin benefits from a clean CVE record and secure SQL practices, the identified code signals, particularly the use of `create_function` and the pervasive lack of output escaping, introduce significant risks that warrant immediate attention.

Key Concerns

  • Dangerous function 'create_function' used
  • Low percentage of output escaping (5%)
  • Bundled outdated library: DataTables v1.9.4
  • Flows with unsanitized paths found (4)
  • AJAX handlers without capability checks
Vulnerabilities
None known

xBooster Social Icons with Counter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

xBooster Social Icons with Counter Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
148
8 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Dangerous Functions Found

create_functionadd_action( 'widgets_init', create_function('', 'return register_widget("Xbooster_Social_Profiles_Wiinc\widget-functions.php:5
create_functionadd_action( 'widgets_init', create_function('', 'return register_widget("Xbooster_Social_Share_Widgeinc\widget-functions.php:6

Bundled Libraries

DataTables1.9.4

Output Escaping

5% escaped156 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

7 flows4 with unsanitized paths
<admin-display-options> (admin\admin-display-options.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

xBooster Social Icons with Counter Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 6

authwp_ajax_xbooster_ajax_followinc\ajax-functions.php:3
noprivwp_ajax_xbooster_ajax_followinc\ajax-functions.php:4
authwp_ajax_xbooster_ajax_shareinc\ajax-functions.php:5
noprivwp_ajax_xbooster_ajax_shareinc\ajax-functions.php:6
authwp_ajax_xbooster_share_sortinc\ajax-functions.php:7
authwp_ajax_xbooster_profile_sortinc\ajax-functions.php:8

Shortcodes 2

[xBooster_Social_Profiles] xbooster-social-icons-with-counter.php:37
[xBooster_Social_Share] xbooster-social-icons-with-counter.php:38
WordPress Hooks 9
filterthe_contentinc\content-render-functions.php:2
actionadmin_enqueue_scriptsinc\script-style-loader.php:2
actionwp_enqueue_scriptsinc\script-style-loader.php:3
actionadmin_print_stylesinc\script-style-loader.php:4
actionwidgets_initinc\widget-functions.php:5
actionwidgets_initinc\widget-functions.php:6
actionplugins_loadedxbooster-social-icons-with-counter.php:14
actioninitxbooster-social-icons-with-counter.php:41
actionadmin_menuxbooster-social-icons-with-counter.php:76
Maintenance & Trust

xBooster Social Icons with Counter Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedJan 5, 2014
PHP min version
Downloads3K

Community Trust

Rating90/100
Number of ratings2
Active installs10
Developer Profile

xBooster Social Icons with Counter Developer Profile

acbaltaci

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect xBooster Social Icons with Counter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xbooster-social-icons-with-counter/assets/css/frontend.css/wp-content/plugins/xbooster-social-icons-with-counter/assets/js/frontend.js
Script Paths
/wp-content/plugins/xbooster-social-icons-with-counter/assets/js/frontend.js
Version Parameters
xbooster-social-icons-with-counter/assets/css/frontend.css?ver=xbooster-social-icons-with-counter/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
xbsp_containerxbsp_actxbooster_followxboostericonbubblexbooster_follow_counterxbooster_share_counter
Data Attributes
data-dodata-noncedata-network
REST Endpoints
admin-ajax.php?action=xbooster_ajax
Shortcode Output
<ul class="xbsp_container"><li class="xbsp_act"><span><li><a class="xbooster_follow"<img class="xboostericon
FAQ

Frequently Asked Questions about xBooster Social Icons with Counter