
AddToAny Share Buttons Security & Risk Analysis
wordpress.org/plugins/add-to-anyShare buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Is AddToAny Share Buttons Safe to Use in 2026?
Generally Safe
Score 99/100AddToAny Share Buttons has a strong security track record. Known vulnerabilities have been patched promptly.
The Add-to-Any plugin version 1.8.16 exhibits a generally good security posture based on the static analysis. It has a small attack surface with no unprotected entry points, uses prepared statements for all SQL queries, and has a high percentage of properly escaped output. The presence of nonce and capability checks further strengthens its defensive mechanisms. The absence of dangerous functions, file operations, and critical/high severity taint flows are also positive indicators.
However, the plugin's vulnerability history is a notable concern. With three known medium severity CVEs, particularly related to Cross-site Scripting and Improper Input Validation, it suggests a recurring pattern of input sanitization weaknesses. Although all historical vulnerabilities are currently patched, the nature of these past issues warrants continued vigilance and a proactive approach to security testing. The single external HTTP request, while not inherently dangerous, could potentially be a vector if the external resource is compromised.
In conclusion, while Add-to-Any version 1.8.16 has implemented several sound security practices, its past vulnerability history, specifically around input handling and cross-site scripting, necessitates careful monitoring and a cautious approach. The strengths in code sanitization and access control are undermined by these historical patterns, suggesting that while the current code might be clean, the underlying architecture may have recurring challenges.
Key Concerns
- Multiple medium CVEs related to XSS and input validation
- One external HTTP request
AddToAny Share Buttons Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
AddToAny Share Buttons <= 1.7.47 - Authenticated Stored Cross-Site Scripting
AddToAny Share Buttons <= 1.7.45 - Authenticated Stored Cross-Site Scripting
AddToAny Share Buttons <= 1.7.14 - HTTP Host Header Injection
AddToAny Share Buttons Code Analysis
Output Escaping
AddToAny Share Buttons Attack Surface
Shortcodes 1
WordPress Hooks 30
Scheduled Events 1
Maintenance & Trust
AddToAny Share Buttons Maintenance & Trust
Maintenance Signals
Community Trust
AddToAny Share Buttons Alternatives
WPUpper Share Buttons
wpupper-share-buttons
Free social share buttons, share to Facebook, WhatsApp, Messenger, Twitter, Reddit and much more.
Social Linkz – Lightweight and fast social media sharing plugin
social-linkz
Social Linkz plugin helps you easily share your content to social media.
Super Simple Social Share Icons
super-simple-social-share-icons
A lightweight and powerful solution for adding beautiful social sharing buttons to your WordPress site.
DR!M Share
drim-share
A simple light-weight and mobile-friendly social sharing plugin for WordPress.
Super Easy Social Share
super-easy-social-share
The plugin adds social share links to your website. Includes content buttons and desktop and mobile floating bar.
AddToAny Share Buttons Developer Profile
2 plugins · 301K total installs
How We Detect AddToAny Share Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-to-any/addtoany.css/wp-content/plugins/add-to-any/addtoany.jsAddToAny Share Buttons/wp-content/plugins/add-to-any/addtoany.jsadd-to-any/addtoany.css?ver=add-to-any/addtoany.js?ver=HTML / DOM Fingerprints
a2a_kita2a_kit_size_32addtoany_lista2a_vertical_styledata-a2a-urldata-a2a-titledata-a2a-mediadata-a2a-scroll-showA2A_SHARE_SAVE_plugin_urlADDTOANY_SHARE_SAVE_BUTTONADDTOANY_SHARE_SAVE_ICONSADDTOANY_SHARE_SAVE_KITA2A_SHARE_SAVE_optionsA2A_SHARE_SAVE_services+1 more[addtoany]