{"id":353273,"date":"2026-08-18T07:48:00","date_gmt":"2026-08-18T07:48:00","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/smsocial\/"},"modified":"2026-08-18T07:47:34","modified_gmt":"2026-08-18T07:47:34","slug":"smsocial","status":"publish","type":"plugin","link":"https:\/\/test.wordpress.org\/plugins\/smsocial\/","author":23464764,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.17.0","stable_tag":"0.17.0","tested":"7.0.4","requires":"6.5","requires_php":"8.1","requires_plugins":null,"header_name":"SMSocial","header_author":"SMitov","header_description":"Free social-network foundation for WordPress with member profiles, activity feeds, people discovery, connections, privacy and security.","assets_banners_color":"","last_updated":"2026-08-18 07:47:34","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/smsocial.uk\/","header_author_uri":"https:\/\/smitov.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":41,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.17.0":{"tag":"0.17.0","author":"stanislavmitov","date":"2026-08-18 07:47:34"}},"upgrade_notice":[],"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.17.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3652308,"resolution":"1","location":"assets","locale":"","width":2554,"height":1395},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3652308,"resolution":"2","location":"assets","locale":"","width":2317,"height":1407},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3652308,"resolution":"3","location":"assets","locale":"","width":2374,"height":1362},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3652308,"resolution":"4","location":"assets","locale":"","width":2430,"height":1378},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3652308,"resolution":"5","location":"assets","locale":"","width":2266,"height":1395},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3652308,"resolution":"6","location":"assets","locale":"","width":2235,"height":1363}},"screenshots":[]},"plugin_section":[],"plugin_tags":[4798,2316,14510,5651,904],"plugin_category":[44],"plugin_contributors":[276208],"plugin_business_model":[],"class_list":["post-353273","plugin","type-plugin","status-publish","hentry","plugin_tags-activity-feed","plugin_tags-community","plugin_tags-connections","plugin_tags-profiles","plugin_tags-social-network","plugin_category-discussion-and-community","plugin_contributors-stanislavmitov","plugin_committers-stanislavmitov"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/smsocial.svg","icon_2x":false,"generated":true},"screenshots":[{"src":"https:\/\/ps.w.org\/smsocial\/assets\/screenshot-1.png?rev=3652308","caption":""},{"src":"https:\/\/ps.w.org\/smsocial\/assets\/screenshot-2.png?rev=3652308","caption":""},{"src":"https:\/\/ps.w.org\/smsocial\/assets\/screenshot-3.png?rev=3652308","caption":""},{"src":"https:\/\/ps.w.org\/smsocial\/assets\/screenshot-4.png?rev=3652308","caption":""},{"src":"https:\/\/ps.w.org\/smsocial\/assets\/screenshot-5.png?rev=3652308","caption":""},{"src":"https:\/\/ps.w.org\/smsocial\/assets\/screenshot-6.png?rev=3652308","caption":""}],"raw_content":"<!--section=description-->\n<p>SMSocial Core provides the free local foundation for building a social community on WordPress. The WordPress.org distribution includes member profiles, canonical activity\/feed publishing, people discovery, follows and connections, privacy controls, account security, responsive application navigation, reactions, comments, sharing and saved activity.<\/p>\n\n<p>This WordPress.org package does not contain paid feature implementations or commercial runtime and does not use an external licence server to unlock functionality. Optional commercial add-ons are distributed separately by SMitov and are not required to use SMSocial Core.<\/p>\n\n<p>SMSocial creates new accounts through email verification. Site owners can configure a transactional email provider before enabling new registrations.<\/p>\n\n<h4>External services<\/h4>\n\n<p>SMSocial does not contact a fixed external service unless a site administrator or member uses a feature that requires it. The following connections can occur:<\/p>\n\n<ul>\n<li>Postmark API (optional transactional email): used only when the administrator selects Postmark and supplies a server token. Recipient email addresses, message content and delivery metadata required to send the message are transmitted when SMSocial sends transactional email. Service: https:\/\/postmarkapp.com\/ ; Terms: https:\/\/postmarkapp.com\/terms-of-service ; Privacy: https:\/\/postmarkapp.com\/privacy-policy<\/li>\n<li>Custom SMTP (optional transactional email): used only when the administrator supplies an SMTP server. Recipient email addresses, message content, delivery metadata and the configured SMTP credentials are sent to that administrator-selected mail server when email is sent. The terms and privacy policy are those of the SMTP provider selected by the administrator.<\/li>\n<li>External link previews: when a member asks SMSocial to preview a public external URL, the site server sends a bounded HTTP GET request to the URL supplied by that member so it can read public title, description, image and article-preview metadata. The remote website receives the normal server network information, the requested URL and HTTP headers; SMSocial's User-Agent also identifies the SMSocial version and the WordPress site's home URL. No SMSocial password or private account credential is sent. Because the destination is chosen by the member rather than being a fixed SMSocial provider, that destination website's own terms and privacy policy apply.<\/li>\n<li>YouTube embedded player: when a post containing a supported YouTube link is viewed, the browser can load the privacy-enhanced YouTube player from youtube-nocookie.com. The video identifier and normal browser\/network request information are sent to Google\/YouTube. Terms: https:\/\/www.youtube.com\/static?template=terms ; Privacy: https:\/\/policies.google.com\/privacy<\/li>\n<li>Vimeo embedded player: when a post containing a supported Vimeo link is viewed, the browser can load player.vimeo.com. The video identifier and normal browser\/network request information are sent to Vimeo. Terms: https:\/\/vimeo.com\/legal\/ ; Privacy: https:\/\/vimeo.com\/privacy<\/li>\n<li>TikTok embedded player: when a post containing a supported TikTok video link is viewed, the browser can load www.tiktok.com\/player\/. The video identifier and normal browser\/network request information are sent to TikTok. Terms: https:\/\/www.tiktok.com\/legal\/page\/eea\/terms-of-service\/en ; Privacy: https:\/\/www.tiktok.com\/legal\/page\/eea\/privacy-policy\/en<\/li>\n<li>Dailymotion embedded player: when a post containing a supported Dailymotion link is viewed, the browser can load www.dailymotion.com\/embed\/. The video identifier and normal browser\/network request information are sent to Dailymotion. Terms: https:\/\/legal.dailymotion.com\/en\/terms-of-use\/ ; Privacy: https:\/\/legal.dailymotion.com\/en\/privacy-policy\/<\/li>\n<\/ul>\n\n<p>These connections are feature-driven; SMSocial does not transmit a site's member database to these providers.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate SMSocial.<\/li>\n<li>Open SMSocial settings and configure the public application page and branding.<\/li>\n<li>Configure transactional email delivery if you want to allow new member registration.<\/li>\n<li>Open the SMSocial application and create or sign in to a member account.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20smsocial%20core%20require%20a%20paid%20licence%3F\"><h3>Does SMSocial Core require a paid licence?<\/h3><\/dt>\n<dd><p>No. The WordPress.org Core plugin is functional without a paid licence.<\/p><\/dd>\n<dt id=\"are%20commercial%20add-ons%20included%20in%20this%20plugin%3F\"><h3>Are commercial add-ons included in this plugin?<\/h3><\/dt>\n<dd><p>No. Commercial add-ons are separate packages distributed outside WordPress.org.<\/p><\/dd>\n<dt id=\"does%20smsocial%20send%20data%20to%20an%20external%20service%20automatically%3F\"><h3>Does SMSocial send data to an external service automatically?<\/h3><\/dt>\n<dd><p>No background third-party transmission is enabled by default. Connections occur only when an administrator configures transactional email, or when a member uses external link-preview\/embed functionality as described in the External services section above.<\/p><\/dd>\n<dt id=\"why%20are%20compiled%20translation%20catalogs%20included%3F\"><h3>Why are compiled translation catalogs included?<\/h3><\/dt>\n<dd><p>SMSocial has its own app and administration language selector, which can be different from the WordPress site language. WordPress.org language packs are preferred when they are available for the selected locale. Bundled Bulgarian, German and Spanish MO catalogs are retained only as runtime fallbacks so the SMSocial language selector remains functional when the corresponding language pack is not installed. Editable PO catalogs are not shipped.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.17.0<\/h4>\n\n<ul>\n<li>First public SMSocial Core release, based on the verified WordPress.org Core line with security hardening and first-load DB bootstrap optimization.<\/li>\n<li>Deep migration\/table\/column\/index validation remains active for activation, DB-version changes and explicit System Health\/diagnostics.<\/li>\n<li>Identity, Social Graph, Activity, Reactions, Comments, Shares and Saved deep health\/count checks now run only during cold validation bootstraps.<\/li>\n<li>Added request-local memoization for schema introspection and migration-ledger reads during deep checks.<\/li>\n<li>The runtime schema stamp is persisted only after the complete SMSocial module graph boots successfully.<\/li>\n<li>DB schema remains 31.<\/li>\n<\/ul>\n\n<h4>0.17.0-beta.2-wporg.9.4.1<\/h4>\n\n<ul>\n<li>Place canonical WordPress nonce verification directly in every SMSocial admin action handler before request data is consumed.<\/li>\n<li>Keep capability checks separate and explicit; no nonce suppression is used.<\/li>\n<li>DB schema remains 31.<\/li>\n<\/ul>\n\n<h4>0.17.0-beta.2-wporg.9.4<\/h4>\n\n<ul>\n<li>Security Audit Gate 1: moved admin-post CSRF enforcement to canonical WordPress nonce verification after capability checks.<\/li>\n<li>Removed the broad admin nonce-warning suppression rather than masking static security findings.<\/li>\n<li>Hardened email-first identify\/resend responses so public callers cannot distinguish existing from new accounts by response shape, while preserving bounded rate limits and the new-account verification email flow.<\/li>\n<li>Kept authentication failures inside SMSocial's redacted diagnostics channel and corrected the corresponding administrator guidance.<\/li>\n<li>Re-reviewed REST authorization, SQL preparation, uploads, SSRF boundaries, redirects, escaping and session controls.<\/li>\n<li>DB schema remains 31.<\/li>\n<\/ul>\n\n<h4>0.17.0-beta.2-wporg.9.3<\/h4>\n\n<ul>\n<li>Rebuilt the Core Code Split from the verified wporg.8.1 UI baseline.<\/li>\n<li>Removed optional commercial backend modules, REST controllers and JavaScript runtime from the Core package.<\/li>\n<li>Preserved the shared frontend and administration shells used by Core features.<\/li>\n<li>Stopped rendering inactive Messages\/Notifications top-bar placeholders in Core; those entry points now appear only when an extension is actually available, and removed the Events development-status card.<\/li>\n<li>Kept schema-31 migration compatibility for existing SMSocial-owned data.<\/li>\n<li>Added a no-persistence extension boundary for separately installed optional add-ons.<\/li>\n<\/ul>\n\n<h4>0.17.0-beta.2-wporg.8<\/h4>\n\n<ul>\n<li>WordPress.org repository hygiene pass.<\/li>\n<li>Closed remaining actionable nonce\/input findings while preserving opaque credentials and validated JSON imports.<\/li>\n<li>Removed direct PHP debug-log sinks from the Core package in favour of the internal redacted diagnostics channel.<\/li>\n<li>Prefixed template-scope variables and made SMSocial social-graph hooks literal.<\/li>\n<li>Documented intentional use of WordPress core lifecycle hooks and cache interoperability constants.<\/li>\n<\/ul>\n\n<h4>0.17.0-beta.2-wporg.6<\/h4>\n\n<ul>\n<li>WordPress.org security-input cleanup and policy-boundary pass.<\/li>\n<li>Added nonce protection to the SMSocial admin-language preference links.<\/li>\n<li>Sanitized read-only route, session, server-context and media selector inputs.<\/li>\n<li>Removed WordPress.org Core licence activation and custom update administration paths.<\/li>\n<\/ul>\n\n<h4>0.17.0-beta.2-wporg.5<\/h4>\n\n<ul>\n<li>Corrected remaining WordPress.org i18n translator-comment and renderer escaping findings.<\/li>\n<\/ul>\n\n<h4>0.17.0-beta.2-wporg.4<\/h4>\n\n<ul>\n<li>WordPress.org error cleanup pass after SQL safety completion.<\/li>\n<li>Added i18n translator metadata and literal legal-page translations.<\/li>\n<li>Removed local process execution from the WordPress.org Core distribution.<\/li>\n<li>Replaced direct file deletion with WordPress file deletion helpers and documented intentional streaming boundaries.<\/li>\n<li>Added Tested up to metadata and direct-template access protection.<\/li>\n<li>No database schema change.<\/li>\n<\/ul>\n\n<h4>0.17.0-beta.2-wporg.3<\/h4>\n\n<ul>\n<li>SQL safety cleanup pass 2: completed prepared identifier\/value cleanup for the remaining dynamic repository queries.<\/li>\n<li>No database schema change.<\/li>\n<\/ul>\n\n<h4>0.17.0-beta.2-wporg.1<\/h4>\n\n<ul>\n<li>First WordPress.org distribution preflight build.<\/li>\n<li>Removed the third-party updater and external licence-server runtime from the WordPress.org package.<\/li>\n<li>Reduced the public product catalogue to free Core capabilities only.<\/li>\n<li>Added WordPress.org-focused documentation and external-service disclosure.<\/li>\n<\/ul>","raw_excerpt":"A modern social-network foundation for WordPress with member profiles, activity feeds, people discovery, connections, privacy and security.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/test.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/353273","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/test.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/test.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/test.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=353273"}],"author":[{"embeddable":true,"href":"https:\/\/test.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/stanislavmitov"}],"wp:attachment":[{"href":"https:\/\/test.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=353273"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/test.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=353273"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/test.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=353273"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/test.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=353273"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/test.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=353273"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/test.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=353273"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}