Social Sharing Plugin – Kiwi Security & Risk Analysis

wordpress.org/plugins/kiwi-social-share

This is by far the best free WordPress share plugin. It is simple yet does exactly what it should with plenty of customisation options.

4K active installs v2.1.8 PHP + WP 4.0+ Updated Jun 29, 2024
facebook-sharesocial-floating-barsocial-media-buttonsocial-share-barsocial-share-button
53
C · Use Caution
CVEs total4
Unpatched1
Last CVESep 5, 2025
Download
Safety Verdict

Is Social Sharing Plugin – Kiwi Safe to Use in 2026?

Use With Caution

Score 53/100

Social Sharing Plugin – Kiwi has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

4 known CVEs 1 unpatched Last CVE: Sep 5, 2025Updated 1yr ago
Risk Assessment

The plugin 'kiwi-social-share' v2.1.8 presents a mixed security posture. While the static analysis indicates a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events directly exposed without authentication, and all SQL queries using prepared statements, several concerning signals emerge. The significant percentage of improperly escaped output (30%) is a considerable risk, as it can lead to Cross-Site Scripting (XSS) vulnerabilities. Additionally, the presence of external HTTP requests without explicit mention of sanitization or authentication raises a potential flag for information disclosure or further attack vectors.

The vulnerability history is a major concern, with a total of four known CVEs, one of which remains unpatched. The types of past vulnerabilities, including XSS, exposure of sensitive information, and missing authorization, are serious and suggest a pattern of recurring security weaknesses. The presence of critical vulnerabilities in the past, even if currently patched, indicates that the plugin's development practices may not consistently prioritize robust security.

In conclusion, while 'kiwi-social-share' v2.1.8 has strengths in its limited attack surface and use of prepared statements for SQL, the high rate of unescaped output and the concerning vulnerability history, particularly the unpatched critical CVE, significantly elevate the risk. Users should exercise extreme caution and prioritize updating to a version that addresses all known vulnerabilities.

Key Concerns

  • Unpatched critical CVE
  • Significant percentage of improperly escaped output
  • Past critical vulnerabilities
  • Exposure of Sensitive Information vulnerability history
  • Missing Authorization vulnerability history
  • External HTTP requests without explicit security checks
Vulnerabilities
4

Social Sharing Plugin – Kiwi Security Vulnerabilities

CVEs by Year

1 CVE in 2018
2018
1 CVE in 2021
2021
1 CVE in 2024
2024
1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Critical
2
Medium
2

4 total CVEs

CVE-2025-58790medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Kiwi <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 5, 2025Unpatched
CVE-2024-3228medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

Social Sharing Plugin – Kiwi <= 2.1.7 - Information Disclosure

Jul 8, 2024 Patched in 2.1.8 (1d)
CVE-2021-4362critical · 9.8Missing Authorization

Kiwi Social Sharing 2.1.0 - 2.1.2 - Arbitrary Options Change

Jun 4, 2021 Patched in 2.1.3 (963d)

Kiwi Social Share <= 2.0.10 - Arbitrary Options Update

Nov 12, 2018 Patched in 2.0.11 (1898d)
Code Analysis
Analyzed Mar 16, 2026

Social Sharing Plugin – Kiwi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
83
197 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

70% escaped280 total outputs
Attack Surface

Social Sharing Plugin – Kiwi Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionplugins_loadedincludes\class-kiwi-social-share.php:115
actionwp_enqueue_scriptsincludes\class-kiwi-social-share.php:118
actionwp_enqueue_scriptsincludes\class-kiwi-social-share.php:119
actionadmin_enqueue_scriptsincludes\class-kiwi-social-share.php:122
actionadmin_enqueue_scriptsincludes\class-kiwi-social-share.php:123
actionadmin_print_styles-post.phpincludes\class-kiwi-social-share.php:126
actionadmin_print_styles-post-new.phpincludes\class-kiwi-social-share.php:127
actioninitincludes\class-kiwi-social-share.php:131
actionwpincludes\frontend\social-bars\class-kiwi-social-share-view-article-bar.php:51
actionwpincludes\frontend\social-bars\class-kiwi-social-share-view-article-bar.php:52
actionthe_contentincludes\frontend\social-bars\class-kiwi-social-share-view-article-bar.php:53
actionwoocommerce_shareincludes\frontend\social-bars\class-kiwi-social-share-view-article-bar.php:73
actionwp_footerincludes\frontend\social-bars\class-kiwi-social-share-view-floating-bar.php:26
Maintenance & Trust

Social Sharing Plugin – Kiwi Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJun 29, 2024
PHP min version
Downloads467K

Community Trust

Rating82/100
Number of ratings18
Active installs4K
Developer Profile

Social Sharing Plugin – Kiwi Developer Profile

WPKube

9 plugins · 238K total installs

66
trust score
Avg Security Score
81/100
Avg Patch Time
725 days
View full developer profile
Detection Fingerprints

How We Detect Social Sharing Plugin – Kiwi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kiwi-social-share/assets/vendors/icomoon/style.css/wp-content/plugins/kiwi-social-share/assets/css/frontend.css/wp-content/plugins/kiwi-social-share/assets/css/frontend.min.css/wp-content/plugins/kiwi-social-share/assets/js/kiwi.js/wp-content/plugins/kiwi-social-share/assets/js/kiwi.min.js/wp-content/plugins/kiwi-social-share/assets/js/frontend.js/wp-content/plugins/kiwi-social-share/assets/js/frontend.min.js
Script Paths
/wp-content/plugins/kiwi-social-share/assets/js/kiwi.js/wp-content/plugins/kiwi-social-share/assets/js/kiwi.min.js/wp-content/plugins/kiwi-social-share/assets/js/frontend.js/wp-content/plugins/kiwi-social-share/assets/js/frontend.min.js
Version Parameters
kiwi-social-share/assets/vendors/icomoon/style.css?ver=kiwi-social-share/assets/css/frontend.css?ver=kiwi-social-share/assets/css/frontend.min.css?ver=kiwi-social-share/assets/js/kiwi.js?ver=kiwi-social-share/assets/js/kiwi.min.js?ver=kiwi-social-share/assets/js/frontend.js?ver=kiwi-social-share/assets/js/frontend.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
kiwi-social-share
Data Attributes
data-network
JS Globals
Kiwi_Social_Sharekiwi_social_share_opts
FAQ

Frequently Asked Questions about Social Sharing Plugin – Kiwi