
All Social Share – Sticky & Floating Share Buttons for WordPress Security & Risk Analysis
wordpress.org/plugins/all-social-shareAdd lightweight, customizable social share buttons for Facebook, Twitter, LinkedIn, WhatsApp, Pinterest, Reddit, and more.
Is All Social Share – Sticky & Floating Share Buttons for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100All Social Share – Sticky & Floating Share Buttons for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'all-social-share' plugin version 1.1.3 exhibits a generally strong security posture based on the static analysis and vulnerability history provided. The absence of any recorded CVEs and the analysis showing zero dangerous functions, SQL queries without prepared statements, file operations, or external HTTP requests are all positive indicators. Furthermore, the lack of detected taint flows with unsanitized paths suggests a careful approach to handling user-supplied data. The high percentage of properly escaped output (89%) is also a good sign, minimizing the risk of cross-site scripting vulnerabilities.
However, the complete lack of capability checks and nonce checks across all identified entry points (even though the attack surface is reported as zero) is a significant concern. While the static analysis found no AJAX handlers, REST API routes, shortcodes, or cron events, this could be an oversight in the analysis or indicate that the plugin might not have any such dynamic functionalities to secure. If these entry points do exist and are not properly secured, it would present a serious vulnerability. The vulnerability history being clean is a strength, but the absence of security mechanisms like capability and nonce checks in the code itself points to a potential foundational weakness if those entry points were to be introduced or are currently overlooked. Overall, the plugin appears safe based on current data but has potential for risk if its attack surface is larger than reported or if security measures are not implemented for any future extensions.
Key Concerns
- No capability checks found
- No nonce checks found
- 11% of output not properly escaped
All Social Share – Sticky & Floating Share Buttons for WordPress Security Vulnerabilities
All Social Share – Sticky & Floating Share Buttons for WordPress Code Analysis
Output Escaping
All Social Share – Sticky & Floating Share Buttons for WordPress Attack Surface
WordPress Hooks 6
Maintenance & Trust
All Social Share – Sticky & Floating Share Buttons for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
All Social Share – Sticky & Floating Share Buttons for WordPress Alternatives
WP Social Share
wp-social-share
Add Social Networks Share Button at Home, Category and Single Posts Pages.
Social Share
kento-social-share
Fancy Social share tool by https://pluginspoint.com
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
Simple Social Media Share Buttons – Social Sharing for Everyone
simple-social-buttons
This Social Share Plugin adds advanced social media sharing buttons to your WordPress sites, such as Facebook, WhatsApp, X, LinkedIn, & Pinterest.
Hide Posts
whp-hide-posts
Allows you to hide any posts on the home page, category page, search page, tags page, authors page, RSS Feed, REST API, XML sitemaps, SEO integrations …
All Social Share – Sticky & Floating Share Buttons for WordPress Developer Profile
13 plugins · 120 total installs
How We Detect All Social Share – Sticky & Floating Share Buttons for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-social-share/css/admin-styles.cssall-social-share/all-social-share.php?ver=all-social-share/includes/class-social-share.php?ver=HTML / DOM Fingerprints
assp_social-share-buttons_newposition-topposition-bottomposition-leftposition-rightdata-social-sharedata-urlassp_color_picker_params