
WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) Security & Risk Analysis
wordpress.org/plugins/e-mailitFree, AI-powered, privacy-first share buttons for WordPress with optional post-share monetization.
Is WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) Safe to Use in 2026?
Mostly Safe
Score 78/100WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) is generally safe to use. 1 past CVE were resolved. Keep it updated.
The e-mailit plugin v13.0.0 exhibits a mixed security posture. On the positive side, the static analysis reveals a clean slate regarding dangerous functions, SQL queries (all prepared), file operations, and external HTTP requests. The presence of nonce checks is also a good sign. However, the extremely low percentage of properly escaped output (7%) is a significant concern, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's vulnerability history which points to XSS as a common issue.
The plugin's attack surface appears to be minimal with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication. Taint analysis also shows no critical or high severity flows, suggesting that direct code execution or data compromise through these vectors might be less likely. Nevertheless, the lack of capability checks on any identified entry points (though none were found) and the poor output escaping practices present substantial risks.
The vulnerability history, specifically one unpatched medium severity CVE related to XSS, reinforces the concerns raised by the static analysis. This suggests a pattern of vulnerabilities in this area that has not been fully addressed. While the plugin demonstrates strengths in several core security areas, the widespread lack of output escaping and the lingering unpatched XSS vulnerability significantly lower its overall security standing.
Key Concerns
- Unpatched medium severity CVE
- Low percentage of properly escaped output
- No capability checks on entry points
WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WeShare Buttons <= 13.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) Code Analysis
Output Escaping
WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) Attack Surface
WordPress Hooks 16
Maintenance & Trust
WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) Maintenance & Trust
Maintenance Signals
Community Trust
WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) Alternatives
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider
fluent-smtp
The Ultimate Forever Free Mail SMTP Plugin for WordPress. Connect with any SMTP, SendGrid, Mailgun, Amazon SES, Brevo, Postmark, Sparkpost, Google...
GoSMTP – SMTP for WordPress
gosmtp
Send emails from your WordPress site using your preferred SMTP provider like Gmail, Outlook, AWS, Zoho, SMTP.com, Brevo (formerly Sendinblue), Mailgun …
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
EmailKit – Email Customizer for WooCommerce & WP
emailkit
EmailKit is a powerful WordPress and WooCommerce email customizer tool, free for everyone! It allows users to customize and design templates that show …
reGenerate Thumbnails Advanced
regenerate-thumbnails-advanced
Regenerate thumbnails quickly and easily, including forced regeneration; very useful when changing a theme or adding new thumbnail sizes.
WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT) Developer Profile
1 plugin · 800 total installs
How We Detect WeShareAI – AI-Powered Share Buttons (formerly E-MAILiT)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/e-mailit/js/toggleswitch/css/toggleswitch.css/wp-content/plugins/e-mailit/js/colorpicker/js/spectrum.min.js/wp-content/plugins/e-mailit/js/fontselect/jquery.fontselector.js/wp-content/plugins/e-mailit/css/style.css/wp-content/plugins/e-mailit/js/jquery-ui.min.js/wp-content/plugins/e-mailit/js/toggleswitch/js/toggleswitch.js/wp-content/plugins/e-mailit/css/jquery-ui.min.css/wp-content/plugins/e-mailit/js/colorpicker/css/spectrum.min.css/wp-content/plugins/e-mailit/js/jquery-ui.min.js/wp-content/plugins/e-mailit/js/colorpicker/js/spectrum.min.js/wp-content/plugins/e-mailit/js/fontselect/jquery.fontselector.js/wp-content/plugins/e-mailit/js/toggleswitch/js/toggleswitch.jsHTML / DOM Fingerprints
emailit-admin-noticeemailit_options