
G Social Buttons Security & Risk Analysis
wordpress.org/plugins/g-social-buttonsG Social Buttons is a plug-in that allows you to add simple social media icons and increase the social media interaction of your website.
Is G Social Buttons Safe to Use in 2026?
Generally Safe
Score 85/100G Social Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "g-social-buttons" v1.0.2 plugin exhibits a generally good security posture concerning its direct entry points and database interactions. The absence of AJAX handlers, REST API routes, and cron events with incomplete security checks significantly limits the plugin's attack surface. Furthermore, all SQL queries utilize prepared statements, which is a critical best practice for preventing SQL injection vulnerabilities. The lack of file operations and external HTTP requests also contributes to a more secure design. However, a significant concern lies in the output escaping. With only 33% of outputs properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities being present. Any user-supplied data that is displayed without proper sanitization could be exploited by attackers. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of past development efforts. However, the current static analysis reveals a weakness that could lead to future vulnerabilities if not addressed. The absence of nonce checks and capability checks on its existing entry points (shortcodes) is also a concern, though the limited nature of shortcodes as entry points mitigates this risk somewhat compared to unprotected AJAX or REST endpoints. In conclusion, while the plugin avoids common critical vulnerabilities like SQL injection and has a clean history, the poor output escaping presents a tangible risk of XSS that needs immediate attention. The lack of capability checks on shortcodes is a secondary concern.
Key Concerns
- Poor output escaping (33% proper)
- Missing capability checks on entry points
- Missing nonce checks on entry points
G Social Buttons Security Vulnerabilities
G Social Buttons Code Analysis
Output Escaping
G Social Buttons Attack Surface
Shortcodes 2
WordPress Hooks 5
Maintenance & Trust
G Social Buttons Maintenance & Trust
Maintenance Signals
Community Trust
G Social Buttons Alternatives
IndoAge Social Share Pro
indoge-social-share-pro
Display floating social media buttons with customizable links, icons, and layouts for better engagement.
Simple Share Buttons Adder
simple-share-buttons-adder
A simple plugin that enables you to add share buttons to all of your posts and/or pages.
Hubbub Lite – Fast, free social sharing and follow buttons
social-pug
Your content is worth sharing. Let's makes it easier!
ShareThis Share Buttons
sharethis-share-buttons
Grow your website traffic and engagement by enabling one-click sharing with the free ShareThis Share Buttons plugin. The plugin is free (no upgrades a …
Simple Social Media Share Buttons – Social Sharing for Everyone
simple-social-buttons
This Social Share Plugin adds advanced social media sharing buttons to your WordPress sites, such as Facebook, WhatsApp, X, LinkedIn, & Pinterest.
G Social Buttons Developer Profile
4 plugins · 10K total installs
How We Detect G Social Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/g-social-buttons/css/style.css/wp-content/plugins/g-social-buttons/css/fontawesome-5-all.min.css/wp-content/plugins/g-social-buttons/css/style.css?ver=/wp-content/plugins/g-social-buttons/css/fontawesome-5-all.min.css?ver=HTML / DOM Fingerprints
sy-whatshelpsywh-open-servicessywh[sywh [call-now