
Ed's Social Share Security & Risk Analysis
wordpress.org/plugins/eds-social-shareAdd beautiful social share buttons for Facebook, X, LinkedIn, TikTok, WhatsApp, Threads, and more with a simple shortcode.
Is Ed's Social Share Safe to Use in 2026?
Mostly Safe
Score 78/100Ed's Social Share is generally safe to use. 1 past CVE were resolved.
The 'eds-social-share' v3.0 plugin exhibits a generally good security posture based on the static analysis, with no critical or high-severity code signals like dangerous functions or unsanitized taint flows. The plugin demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries, a high percentage of properly escaped output, and implementing both nonce and capability checks. The attack surface is minimal and appears to be protected.
However, a significant concern arises from the plugin's vulnerability history. The presence of one known, currently unpatched medium-severity CVE, specifically related to Cross-Site Scripting (XSS), is a critical indicator of risk. While the current version's static analysis doesn't reveal this specific vulnerability, its historical occurrence suggests a potential for such issues to reappear or be present in subtle forms. The fact that a vulnerability of this type was patched relatively recently (though the provided date is in the future, assuming it represents a past event for analysis) and is still unpatched in the current analysis is a major red flag.
In conclusion, while the code itself appears well-written with many security best practices implemented, the unpatched historical CVE significantly elevates the risk profile. Users should be aware that despite the positive static analysis, a known XSS vulnerability remains unaddressed, making the plugin a potential target for attackers.
Key Concerns
- Unpatched CVE exists
Ed's Social Share Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Ed's Social Share <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Ed's Social Share Release Timeline
Ed's Social Share Code Analysis
Output Escaping
Ed's Social Share Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Ed's Social Share Maintenance & Trust
Maintenance Signals
Community Trust
Ed's Social Share Alternatives
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Crafty Social Buttons
crafty-social-buttons
Adds social sharing and link buttons, including Ravelry, Etsy, Craftsy and Pinterest.
Social Icons Sticky
share-social-media
Add social sharing icons to a post or page of your WordPress website and allow visitors to share your content on various social media sites.
Conversions Extensions
conversions-extensions
Adds homepage sections, one click demo imports, social icons, and other features to Conversions theme for WordPress.
WP Custom Social Sharing
wp-custom-social-sharing
WP Custom Social Sharing is a free WordPress plugin that makes any content on you website social-share-friendly by allowing anyone easily share their …
Ed's Social Share Developer Profile
2 plugins · 0 total installs
How We Detect Ed's Social Share
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eds-social-share/css/styles.css/wp-content/plugins/eds-social-share/css/all.min.csseds-social-share/css/styles.css?ver=eds-social-share/css/all.min.css?ver=HTML / DOM Fingerprints
ess-smalless-mediumess-large<!-- Ed's Social Share - Open Graph Tags --><!-- / Ed's Social Share --><!-- Ed's Social Share --><!-- / Ed's Social Share -->+2 moreess_og_imageess_og_nonceess_og_nonce_fieldname="ess_og_image"value="onclick="var frame=wp.media({title:'Select Share Image',multiple:false});frame.on('select',function(){var url=frame.state().get('selection').first().toJSON().url;document.querySelector('input[name=ess_og_image]').value=url;});frame.open();"wp.media<div style="text-align:center" class="wrapper <h2 style="text-align:center; color:Share Us