Easy Social Icons Security & Risk Analysis
wordpress.org/plugins/easy-social-iconsUpload your own social media icons or choose from font-awesome. Use widget|shortcode to place icons anywhere(sidebar, header, footer, page) in theme.
Is Easy Social Icons Safe to Use in 2026?
Generally Safe
Score 96/100Easy Social Icons has a strong security track record. Known vulnerabilities have been patched promptly.
The security posture of easy-social-icons v4.0.2 presents a mixed bag of good practices and significant concerns. While the plugin demonstrates some strengths, such as a relatively contained attack surface with no explicitly unprotected entry points in the static analysis and a decent percentage of SQL queries using prepared statements, the overall picture is marred by a concerning vulnerability history. The presence of 12 known CVEs, including a substantial number of high and medium severity vulnerabilities in the past, suggests a pattern of recurring security weaknesses. Furthermore, the static analysis reveals a flow with an unsanitized path and a high-severity taint flow, which are immediate red flags indicating potential for exploitation.
Key Concerns
- High severity taint flow detected
- Flow with unsanitized path detected
- 50% of SQL queries not using prepared statements
- 33% of output not properly escaped
- 12 total known CVEs in history
- 3 high severity historical CVEs
- 9 medium severity historical CVEs
Easy Social Icons Security Vulnerabilities
CVEs by Year
Severity Breakdown
12 total CVEs
Easy Social Icons <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
Easy Social Icons <= 3.2.4 - Missing Authorization via cnss_save_ajax_order
Easy Social Icons <= 3.1.4 - Admin+ Cross-Site Scripting
Easy Social Icons <= 3.2.0 - Authenticated (Admin+) Cross-Site Scripting and Missing Authorization Checks
Easy Social Icons <= 3.2.2 - Admin+ Cross-Site Scripting
Easy Social Icons <= 3.2.0 - Admin+ Stored Cross-Site Scripting
Easy Social Icons <= 3.1.3 - Admin+ SQL Injection
Easy Social Icons <= 3.1.2 - Reflected Cross-Site Scripting
Easy Social Icons <= 3.0.9 - Reflected Cross-Site Scripting
Easy Social Icons <= 3.0.8 – Reflected Cross-Site Scripting
Easy Social Icons <= 1.2.3.1 - SQL Injection
Easy Social Icons <= 1.2.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Easy Social Icons Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Easy Social Icons Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Easy Social Icons Maintenance & Trust
Maintenance Signals
Community Trust
Easy Social Icons Alternatives
Social Share Buttons
share-button
Our Share Button addon to MaxButtons and MaxButtons Pro plugins gets you up and sharing within minutes. It's easy to setup and offers flexibility …
Social Icons Sticky
share-social-media
Add social sharing icons to a post or page of your WordPress website and allow visitors to share your content on various social media sites.
Advanced Social icons
advance-social-icons
Advanced social icons help you quickly add icons with links to your profile on different social media platforms.
Super Simple Social Share Icons
super-simple-social-share-icons
A lightweight and powerful solution for adding beautiful social sharing buttons to your WordPress site.
DP Easy Social Share
dp-easy-social-share
A lightweight, customizable social sharing plugin for WordPress that adds social icons to your posts, pages and custom post types.
Easy Social Icons Developer Profile
5 plugins · 31K total installs
How We Detect Easy Social Icons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-social-icons/assets/css/cnss-font.css/wp-content/plugins/easy-social-icons/assets/css/cnss.css/wp-content/plugins/easy-social-icons/assets/css/cnss-style.css/wp-content/plugins/easy-social-icons/assets/js/cnss.js/wp-content/plugins/easy-social-icons/assets/js/cnss-custom.js/wp-content/plugins/easy-social-icons/assets/js/backend/cnss-backend.js/wp-content/plugins/easy-social-icons/assets/js/frontend/cnss-frontend.js/wp-content/plugins/easy-social-icons/assets/js/cnss.js/wp-content/plugins/easy-social-icons/assets/js/cnss-custom.js/wp-content/plugins/easy-social-icons/assets/js/backend/cnss-backend.js/wp-content/plugins/easy-social-icons/assets/js/frontend/cnss-frontend.jseasy-social-icons/assets/css/cnss-font.css?ver=easy-social-icons/assets/css/cnss.css?ver=easy-social-icons/assets/css/cnss-style.css?ver=easy-social-icons/assets/js/cnss.js?ver=easy-social-icons/assets/js/cnss-custom.js?ver=easy-social-icons/assets/js/backend/cnss-backend.js?ver=easy-social-icons/assets/js/frontend/cnss-frontend.js?ver=HTML / DOM Fingerprints
cnss-social-icon-containercnss-social-iconcnss-social-icon-textcnss_admin_bannerpro-adspro-ads-feature<!-- Easy Social Icons Premium Advantage -->data-icon-iddata-icon-ordercnss_order_datacnss_admin_obj[cn-social-icon]