Add To Social Security & Risk Analysis

wordpress.org/plugins/add-to-social

Add To Social - Share your posts

10 active installs v0.4.1 PHP + WP 2.0.2+ Updated Jul 13, 2010
bookmarksbuttonssharesocialsocial-sharing
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Add To Social Safe to Use in 2026?

Generally Safe

Score 85/100

Add To Social has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The 'add-to-social' v0.4.1 plugin exhibits a mixed security posture. While the absence of known CVEs and a lack of dangerous function usage are positive indicators, significant concerns arise from the static analysis. The complete absence of nonce checks and capability checks, coupled with a file operation and a taint flow with unsanitized paths, represent potential vulnerabilities that are not mitigated by authentication checks on entry points. The fact that 100% of SQL queries use prepared statements is a strong security practice, but it is overshadowed by the lack of output escaping on all identified outputs and the presence of a taint flow with an unsanitized path. The vulnerability history is clean, which is encouraging, but it does not negate the risks identified in the current code analysis. Overall, while the plugin has avoided historical vulnerabilities, the current codebase has critical areas that require immediate attention due to potential for code injection or unauthorized file access.

Key Concerns

  • Unsanitized path taint flow
  • No nonce checks
  • No capability checks
  • Unescaped output on all outputs
  • File operations without explicit security context
Vulnerabilities
None known

Add To Social Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Add To Social Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<add-to-social-admin> (add-to-social-admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Add To Social Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterthe_contentadd-to-social.php:172
actionadmin_menuadd-to-social.php:182
Maintenance & Trust

Add To Social Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedJul 13, 2010
PHP min version
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Add To Social Developer Profile

svil4ok

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Add To Social

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-to-social/images/edno23.png/wp-content/plugins/add-to-social/images/favit.png/wp-content/plugins/add-to-social/images/svejo.png/wp-content/plugins/add-to-social/images/twitter.png/wp-content/plugins/add-to-social/images/facebook.png/wp-content/plugins/add-to-social/images/google-buzz.png/wp-content/plugins/add-to-social/images/delicious.png/wp-content/plugins/add-to-social/images/google.png+10 more

HTML / DOM Fingerprints

Shortcode Output
[add-to-social]
FAQ

Frequently Asked Questions about Add To Social