
BST share iT Security & Risk Analysis
wordpress.org/plugins/bst-share-itBST share iT - Die Social-Sharing-Buttons die nicht nach Hause telefonieren und geltendes deutsches Recht beachten.
Is BST share iT Safe to Use in 2026?
Generally Safe
Score 85/100BST share iT has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bst-share-it" v1.0.9 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are accessible without authentication. Furthermore, the plugin has no recorded vulnerability history, indicating a lack of publicly disclosed security flaws. This absence of past issues can be a positive indicator of developer diligence.
However, there are several concerning signals within the code. The use of the `create_function` is a significant red flag, as it is deprecated and can lead to security vulnerabilities if not handled with extreme care, potentially allowing for code injection. The SQL query handling is also suboptimal, with only 50% of queries using prepared statements, leaving the other half vulnerable to SQL injection. Additionally, a very low percentage (20%) of output is properly escaped, which presents a high risk of Cross-Site Scripting (XSS) vulnerabilities across various output points. The taint analysis, while limited, did identify a flow with unsanitized paths, which warrants attention despite not being classified as critical or high severity at this time.
In conclusion, while the plugin's attack surface and historical vulnerability record are strengths, the presence of `create_function`, a high rate of unescaped output, and partially unsanitized SQL queries represent significant weaknesses that could be exploited. These code-level concerns outweigh the apparent lack of public vulnerabilities and the small attack surface, suggesting that the plugin should be treated with caution and that these specific code issues need to be addressed.
Key Concerns
- Use of create_function
- Low percentage of properly escaped output
- SQL queries not using prepared statements
- Flows with unsanitized paths
BST share iT Security Vulnerabilities
BST share iT Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
BST share iT Attack Surface
WordPress Hooks 15
Maintenance & Trust
BST share iT Maintenance & Trust
Maintenance Signals
Community Trust
BST share iT Alternatives
Official Markerly Widget
official-markerly-widget
Instant sharing on text highlight/selection to Facebook/Twitter and more!
social share
smart-social-pack
social share lets you add Social Share Buttons, liniking social profile, fb page like box in your website!
Insert Html Snippet
insert-html-snippet
Add HTML, CSS and javascript code to your pages and posts easily using shortcodes.
Uptolike Social Share Buttons
uptolike-share
Uptolike Social Share Buttons - social bookmarking widget with sharing statistics.
HivePress Claim Listings
hivepress-claim-listings
Charge users for claiming listings.
BST share iT Developer Profile
2 plugins · 5K total installs
How We Detect BST share iT
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bst-share-it/js/bst.js/wp-content/plugins/bst-share-it/tools/cp/js/colpick.js/wp-content/plugins/bst-share-it/tools/fl/js/featherlight.min.js/wp-content/plugins/bst-share-it/css/bst_share_it.css/wp-content/plugins/bst-share-it/tools/cp/css/colpick.css/wp-content/plugins/bst-share-it/tools/fl/css/featherlight.min.css/wp-content/plugins/bst-share-it/js/admin.js/wp-content/plugins/bst-share-it/js/upload.js+1 morejs/bst.jstools/cp/js/colpick.jstools/fl/js/featherlight.min.jsjs/admin.jsjs/upload.jsbst_share_it/style.css?ver=bst_share_it/bst_share_it.css?ver=bst_share_it/bst_share_it-admin.css?ver=HTML / DOM Fingerprints
<!-- -->