Findings
- Uses APIs to get the number of likes/shares/etc directly from Facebook, Twitter, Google+, Pinterest
- Uses an HTTP URL for communicating with Pinterest despite the API also working with HTTPS
- Has a feedback form with no CSRF-protection. But the form only sends emails to support@devpups.com
Reason for the 'Potentially unsafe' result
The plugin contains or is likely to contain a vulnerability which could be exploited by an end user and which would compromise the site’s confidentiality, integrity or availability: