WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) Security & Risk Analysis

wordpress.org/plugins/e-mailit

Free, AI-powered, privacy-first share buttons for WordPress with optional post-share monetization.

800 active installs v13.0.0 PHP 5.6+ WP 4.5+ Updated Jan 15, 2026
aiprivacy-firstshare-buttonssocial-sharingwordpress
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVESep 26, 2025
Safety Verdict

Is WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) Safe to Use in 2026?

Mostly Safe

Score 78/100

WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Sep 26, 2025Updated 2mo ago
Risk Assessment

The e-mailit plugin v13.0.0 exhibits a mixed security posture. On the positive side, the static analysis reveals a clean slate regarding dangerous functions, SQL queries (all prepared), file operations, and external HTTP requests. The presence of nonce checks is also a good sign. However, the extremely low percentage of properly escaped output (7%) is a significant concern, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's vulnerability history which points to XSS as a common issue.

The plugin's attack surface appears to be minimal with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication. Taint analysis also shows no critical or high severity flows, suggesting that direct code execution or data compromise through these vectors might be less likely. Nevertheless, the lack of capability checks on any identified entry points (though none were found) and the poor output escaping practices present substantial risks.

The vulnerability history, specifically one unpatched medium severity CVE related to XSS, reinforces the concerns raised by the static analysis. This suggests a pattern of vulnerabilities in this area that has not been fully addressed. While the plugin demonstrates strengths in several core security areas, the widespread lack of output escaping and the lingering unpatched XSS vulnerability significantly lower its overall security standing.

Key Concerns

  • Unpatched medium severity CVE
  • Low percentage of properly escaped output
  • No capability checks on entry points
Vulnerabilities
1

WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-60135medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WeShare Buttons <= 13.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 26, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
43
3 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

7% escaped46 total outputs
Attack Surface

WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionsave_postemailit_post_metabox.php:10
filterdefault_hidden_meta_boxesemailit_post_metabox.php:12
actionadmin_initemailit_post_metabox.php:61
actionadmin_initemailit_widget.php:32
actionwidgets_initemailit_widget.php:33
actionwp_heademailit_widget.php:34
filterget_the_excerptemailit_widget.php:35
actionplugins_loadedemailit_widget.php:36
actionadmin_noticesemailit_widget.php:38
actionadmin_initemailit_widget.php:39
actionadmin_print_stylesemailit_widget.php:58
actionadmin_print_scriptsemailit_widget.php:59
actioninitemailit_widget.php:227
filterthe_contentemailit_widget.php:236
actionwp_footeremailit_widget.php:334
filteradmin_menuinclude\emailit_admin_panel.php:4
Maintenance & Trust

WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 15, 2026
PHP min version5.6
Downloads352K

Community Trust

Rating86/100
Number of ratings65
Active installs800
Developer Profile

WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) Developer Profile

NIKITAS GEORGOPOULOS

1 plugin · 800 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/e-mailit/js/toggleswitch/css/toggleswitch.css/wp-content/plugins/e-mailit/js/colorpicker/js/spectrum.min.js/wp-content/plugins/e-mailit/js/fontselect/jquery.fontselector.js/wp-content/plugins/e-mailit/css/style.css/wp-content/plugins/e-mailit/js/jquery-ui.min.js/wp-content/plugins/e-mailit/js/toggleswitch/js/toggleswitch.js/wp-content/plugins/e-mailit/css/jquery-ui.min.css/wp-content/plugins/e-mailit/js/colorpicker/css/spectrum.min.css
Script Paths
/wp-content/plugins/e-mailit/js/jquery-ui.min.js/wp-content/plugins/e-mailit/js/colorpicker/js/spectrum.min.js/wp-content/plugins/e-mailit/js/fontselect/jquery.fontselector.js/wp-content/plugins/e-mailit/js/toggleswitch/js/toggleswitch.js

HTML / DOM Fingerprints

CSS Classes
emailit-admin-notice
JS Globals
emailit_options
FAQ

Frequently Asked Questions about WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT)