
Crafty Social Buttons Security & Risk Analysis
wordpress.org/plugins/crafty-social-buttonsAdds social sharing and link buttons, including Ravelry, Etsy, Craftsy and Pinterest.
Is Crafty Social Buttons Safe to Use in 2026?
Generally Safe
Score 85/100Crafty Social Buttons has a strong security track record. Known vulnerabilities have been patched promptly.
The "crafty-social-buttons" v1.5.8 plugin exhibits a mixed security posture. While the static analysis indicates a relatively small attack surface with no directly exposed unprotected entry points, several code signals raise concerns. The presence of the `create_function` is a significant red flag, often leading to security vulnerabilities. Furthermore, the complete lack of prepared statements for SQL queries is highly problematic, exposing the application to SQL injection risks. A substantial portion of output is not properly escaped, increasing the likelihood of Cross-Site Scripting (XSS) vulnerabilities. The plugin's vulnerability history, though currently unpatched and dating back to 2017, shows a past medium-severity XSS vulnerability, reinforcing the concerns about output handling.
Despite the lack of critical or high-severity taint flows and the presence of some nonce and capability checks, the identified code signals (especially `create_function` and raw SQL) and the historical XSS vulnerability point to significant potential risks if not addressed. The plugin's outdated nature and past security issues suggest a need for thorough review and potential refactoring to align with modern secure coding practices. The absence of recent vulnerabilities might be due to infrequent use or lack of recent security auditing, rather than inherent security robustness. Therefore, while the plugin doesn't appear to have immediate critical exploitable flaws based solely on this analysis, its underlying code quality suggests a heightened risk profile.
Key Concerns
- Dangerous function 'create_function' found
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- Flow with unsanitized paths found
- Past medium severity XSS vulnerability
Crafty Social Buttons Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Crafty Social Buttons < 1.5.8 - Cross-Site Scripting
Crafty Social Buttons Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Crafty Social Buttons Attack Surface
AJAX Handlers 2
Shortcodes 3
WordPress Hooks 13
Maintenance & Trust
Crafty Social Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Crafty Social Buttons Alternatives
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Hubbub Lite – Fast, free social sharing and follow buttons
social-pug
Your content is worth sharing. Let's makes it easier!
ShareThis Share Buttons
sharethis-share-buttons
Grow your website traffic and engagement by enabling one-click sharing with the free ShareThis Share Buttons plugin. The plugin is free (no upgrades a …
Simple Social Media Share Buttons – Social Sharing for Everyone
simple-social-buttons
This Social Share Plugin adds advanced social media sharing buttons to your WordPress sites, such as Facebook, WhatsApp, X, LinkedIn, & Pinterest.
Social Media Feather | social media sharing
social-media-feather
Lightweight, modern looking and effective social media sharing and profile buttons and icons. All your social media needs in 1 easy package!
Crafty Social Buttons Developer Profile
1 plugin · 1K total installs
How We Detect Crafty Social Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/crafty-social-buttons/css/public.min.css/wp-content/plugins/crafty-social-buttons/js/public.min.jsjs/public.min.jscrafty-social-buttons/css/public.min.css?ver=crafty-social-buttons/js/public.min.js?ver=HTML / DOM Fingerprints
crafty-social-buttonscrafty-social-buttondata-crafty-social-urlcrafty_social_buttons_vars[crafty_social_buttons]