xBooster Social Icons with Counter Security & Risk Analysis
wordpress.org/plugins/xbooster-social-icons-with-counterxBooster social icons with counter is providing, icons for social network sharing and social profile links as widget, shortcode and autoplacement in c …
Is xBooster Social Icons with Counter Safe to Use in 2026?
Generally Safe
Score 85/100xBooster Social Icons with Counter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'xbooster-social-icons-with-counter' plugin version 1.0, based on the provided static analysis and vulnerability history, presents a mixed security posture. A significant strength is the absence of known CVEs and a complete reliance on prepared statements for SQL queries, indicating good practices in database interaction. Furthermore, the total lack of REST API routes and cron events, combined with a low number of total entry points, suggests a relatively contained attack surface. However, there are concerning signals within the code analysis. The presence of two instances of `create_function` is a critical red flag, as this is a deprecated and potentially dangerous PHP function that can lead to code execution vulnerabilities if not handled with extreme care. The extremely low percentage of properly escaped output (5%) is another major concern, as it signifies a high risk of Cross-Site Scripting (XSS) vulnerabilities across numerous output points. While the plugin implements nonce checks and capability checks on some entry points (4 and 0 respectively), the lack of capability checks on AJAX handlers is a weakness that could be exploited if an attacker can trigger these handlers.
The vulnerability history shows no recorded vulnerabilities, which is a positive indicator. However, this should not be taken as a guarantee of current security, especially given the code signals like `create_function` and poor output escaping. The absence of past vulnerabilities might simply mean that these specific weaknesses have not been discovered or exploited yet. In conclusion, while the plugin benefits from a clean CVE record and secure SQL practices, the identified code signals, particularly the use of `create_function` and the pervasive lack of output escaping, introduce significant risks that warrant immediate attention.
Key Concerns
- Dangerous function 'create_function' used
- Low percentage of output escaping (5%)
- Bundled outdated library: DataTables v1.9.4
- Flows with unsanitized paths found (4)
- AJAX handlers without capability checks
xBooster Social Icons with Counter Security Vulnerabilities
xBooster Social Icons with Counter Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
xBooster Social Icons with Counter Attack Surface
AJAX Handlers 6
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
xBooster Social Icons with Counter Maintenance & Trust
Maintenance Signals
Community Trust
xBooster Social Icons with Counter Alternatives
Simple Social Icons
simple-social-icons
This plugin provides two ways to display social icons: a traditional widget (available on all WordPress versions) and block variations for the core So …
Lightweight Social Icons
lightweight-social-icons
Looking to add simple social icons to your widget areas? Choose the size and color of your icons, and then choose from 47 different social profiles.
Socials Ignited
socials-ignited
The Socials Ignited plugin gives you a widget, allowing you to display and link icons on your website of more than 50 social networks.
The Social Links
the-social-links
The Social Links plugin adds a widget and shortcode to your WordPress website allowing you to display icons linking to your social profiles.
BuddyPress Edit Activity
buddypress-edit-activity
BuddyPress Edit Activity allows your members to edit their activity posts on the front-end of your BuddyPress-powered site.
xBooster Social Icons with Counter Developer Profile
2 plugins · 20 total installs
How We Detect xBooster Social Icons with Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/xbooster-social-icons-with-counter/assets/css/frontend.css/wp-content/plugins/xbooster-social-icons-with-counter/assets/js/frontend.js/wp-content/plugins/xbooster-social-icons-with-counter/assets/js/frontend.jsxbooster-social-icons-with-counter/assets/css/frontend.css?ver=xbooster-social-icons-with-counter/assets/js/frontend.js?ver=HTML / DOM Fingerprints
xbsp_containerxbsp_actxbooster_followxboostericonbubblexbooster_follow_counterxbooster_share_counterdata-dodata-noncedata-networkadmin-ajax.php?action=xbooster_ajax<ul class="xbsp_container"><li class="xbsp_act"><span><li><a class="xbooster_follow"<img class="xboostericon