Yet Another Social Media Icon Plugin (YASIP) Security & Risk Analysis

wordpress.org/plugins/yasip

By simply dragging this widget into your sidebar or any widgetized area, you can easily place icon links to your various social profiles.

100 active installs v1.2 PHP + WP 3.0+ Updated Feb 11, 2020
social-iconssocial-mediasocial-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Yet Another Social Media Icon Plugin (YASIP) Safe to Use in 2026?

Generally Safe

Score 85/100

Yet Another Social Media Icon Plugin (YASIP) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "yasip" v1.2 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis shows a commendable commitment to security, with no dangerous functions identified, all SQL queries using prepared statements, and a high percentage of output properly escaped. The lack of file operations, external HTTP requests, and the absence of reported vulnerabilities further contribute to this positive assessment.

However, there are a few areas that warrant attention. The complete absence of nonce checks and capability checks across all code signals is a significant concern, especially if any functionality is introduced later or if the current lack of entry points is misleading. This means that even if there are no direct entry points currently exposed, any future addition of such points would be inherently insecure without these fundamental security measures. The fact that no taint analysis was performed and no vulnerabilities have ever been recorded could indicate either extremely robust code or simply a lack of deep scrutiny over time. Without ongoing proactive security testing, this can become a weakness.

In conclusion, "yasip" v1.2 demonstrates good development practices in areas like SQL and output handling. The limited attack surface is a major strength. The primary weakness lies in the complete omission of nonce and capability checks, which represents a potential for future vulnerabilities if the plugin's functionality expands or is used in unexpected ways. While the plugin has no recorded vulnerability history, this should not be mistaken for guaranteed future safety, particularly given the lack of essential security checks.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • No taint analysis performed
Vulnerabilities
None known

Yet Another Social Media Icon Plugin (YASIP) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Yet Another Social Media Icon Plugin (YASIP) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
47 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

76% escaped62 total outputs
Attack Surface

Yet Another Social Media Icon Plugin (YASIP) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initplugin.php:21
Maintenance & Trust

Yet Another Social Media Icon Plugin (YASIP) Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedFeb 11, 2020
PHP min version
Downloads10K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

Yet Another Social Media Icon Plugin (YASIP) Developer Profile

mitchbartlett

2 plugins · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Yet Another Social Media Icon Plugin (YASIP)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yasip/images//wp-content/plugins/yasip/images/default//wp-content/plugins/yasip/images/default/rss_24x24.png/wp-content/plugins/yasip/images/default/twitter_24x24.png/wp-content/plugins/yasip/images/default/facebook_24x24.png/wp-content/plugins/yasip/images/default/linkedin_24x24.png/wp-content/plugins/yasip/images/default/youtube_24x24.png/wp-content/plugins/yasip/images/default/flickr_24x24.png+20 more

HTML / DOM Fingerprints

CSS Classes
yasip
Data Attributes
id="yasip-widget-title"name="yasip-widget-title"id="yasip-widget-new_window"name="yasip-widget-new_window"id="yasip-widget-icon_set"name="yasip-widget-icon_set"+2 more
FAQ

Frequently Asked Questions about Yet Another Social Media Icon Plugin (YASIP)