Ed's Social Share Security & Risk Analysis

wordpress.org/plugins/eds-social-share

Add beautiful social share buttons for Facebook, X, LinkedIn, TikTok, WhatsApp, Threads, and more with a simple shortcode.

0 active installs v3.0 PHP 7.0+ WP 6.8+ Updated Apr 9, 2026
eds-social-shareiconsshortcodesocial-iconssocial-sharing
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEMar 20, 2026
Safety Verdict

Is Ed's Social Share Safe to Use in 2026?

Mostly Safe

Score 78/100

Ed's Social Share is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Mar 20, 2026Updated 1mo ago
Risk Assessment

The 'eds-social-share' v3.0 plugin exhibits a generally good security posture based on the static analysis, with no critical or high-severity code signals like dangerous functions or unsanitized taint flows. The plugin demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries, a high percentage of properly escaped output, and implementing both nonce and capability checks. The attack surface is minimal and appears to be protected.

However, a significant concern arises from the plugin's vulnerability history. The presence of one known, currently unpatched medium-severity CVE, specifically related to Cross-Site Scripting (XSS), is a critical indicator of risk. While the current version's static analysis doesn't reveal this specific vulnerability, its historical occurrence suggests a potential for such issues to reappear or be present in subtle forms. The fact that a vulnerability of this type was patched relatively recently (though the provided date is in the future, assuming it represents a past event for analysis) and is still unpatched in the current analysis is a major red flag.

In conclusion, while the code itself appears well-written with many security best practices implemented, the unpatched historical CVE significantly elevates the risk profile. Users should be aware that despite the positive static analysis, a known XSS vulnerability remains unaddressed, making the plugin a potential target for attackers.

Key Concerns

  • Unpatched CVE exists
Vulnerabilities
1 published

Ed's Social Share Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-2501medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Ed's Social Share <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Mar 20, 2026Unpatched
Version History

Ed's Social Share Release Timeline

v3.0Current1 CVE
v2.11 CVE
v2.01 CVE
v1.01 CVE
Code Analysis
Analyzed Apr 16, 2026

Ed's Social Share Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
57 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped67 total outputs
Attack Surface

Ed's Social Share Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[social_share] eds_social_share.php:146
WordPress Hooks 7
actioniniteds_social_share.php:22
actionadmin_menueds_social_share.php:23
actionadmin_initeds_social_share.php:24
actionwp_headeds_social_share.php:25
actionadd_meta_boxeseds_social_share.php:99
actionsave_posteds_social_share.php:100
actionwp_enqueue_scriptseds_social_share.php:132
Maintenance & Trust

Ed's Social Share Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 9, 2026
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Ed's Social Share Developer Profile

waianaeboy702

2 plugins · 0 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ed's Social Share

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eds-social-share/css/styles.css/wp-content/plugins/eds-social-share/css/all.min.css
Version Parameters
eds-social-share/css/styles.css?ver=eds-social-share/css/all.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
ess-smalless-mediumess-large
HTML Comments
<!-- Ed's Social Share - Open Graph Tags --><!-- / Ed's Social Share --><!-- Ed's Social Share --><!-- / Ed's Social Share -->+2 more
Data Attributes
ess_og_imageess_og_nonceess_og_nonce_fieldname="ess_og_image"value="onclick="var frame=wp.media({title:'Select Share Image',multiple:false});frame.on('select',function(){var url=frame.state().get('selection').first().toJSON().url;document.querySelector('input[name=ess_og_image]').value=url;});frame.open();"
JS Globals
wp.media
Shortcode Output
<div style="text-align:center" class="wrapper <h2 style="text-align:center; color:Share Us
FAQ

Frequently Asked Questions about Ed's Social Share