
Social Sharing Plugin – Kiwi Security & Risk Analysis
wordpress.org/plugins/kiwi-social-shareThis is by far the best free WordPress share plugin. It is simple yet does exactly what it should with plenty of customisation options.
Is Social Sharing Plugin – Kiwi Safe to Use in 2026?
Use With Caution
Score 53/100Social Sharing Plugin – Kiwi has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin 'kiwi-social-share' v2.1.8 presents a mixed security posture. While the static analysis indicates a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events directly exposed without authentication, and all SQL queries using prepared statements, several concerning signals emerge. The significant percentage of improperly escaped output (30%) is a considerable risk, as it can lead to Cross-Site Scripting (XSS) vulnerabilities. Additionally, the presence of external HTTP requests without explicit mention of sanitization or authentication raises a potential flag for information disclosure or further attack vectors.
The vulnerability history is a major concern, with a total of four known CVEs, one of which remains unpatched. The types of past vulnerabilities, including XSS, exposure of sensitive information, and missing authorization, are serious and suggest a pattern of recurring security weaknesses. The presence of critical vulnerabilities in the past, even if currently patched, indicates that the plugin's development practices may not consistently prioritize robust security.
In conclusion, while 'kiwi-social-share' v2.1.8 has strengths in its limited attack surface and use of prepared statements for SQL, the high rate of unescaped output and the concerning vulnerability history, particularly the unpatched critical CVE, significantly elevate the risk. Users should exercise extreme caution and prioritize updating to a version that addresses all known vulnerabilities.
Key Concerns
- Unpatched critical CVE
- Significant percentage of improperly escaped output
- Past critical vulnerabilities
- Exposure of Sensitive Information vulnerability history
- Missing Authorization vulnerability history
- External HTTP requests without explicit security checks
Social Sharing Plugin – Kiwi Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Kiwi <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Social Sharing Plugin – Kiwi <= 2.1.7 - Information Disclosure
Kiwi Social Sharing 2.1.0 - 2.1.2 - Arbitrary Options Change
Kiwi Social Share <= 2.0.10 - Arbitrary Options Update
Social Sharing Plugin – Kiwi Code Analysis
Output Escaping
Social Sharing Plugin – Kiwi Attack Surface
WordPress Hooks 13
Maintenance & Trust
Social Sharing Plugin – Kiwi Maintenance & Trust
Maintenance Signals
Community Trust
Social Sharing Plugin – Kiwi Alternatives
Coming Soon Page Maintenance Mode Under Construction Page
et-coming-soon-page-maintenance-mode-under-construction-page
Elegant looking coming soon page, Maintenance Mode & Under construction page. Put your site under maintenance in minutes.
Plain Social Sharing Buttons
plain-social-sharing-buttons
Simple and lightweight social sharing buttons for your wordpress site
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
Custom Share Buttons with Floating Sidebar
custom-share-buttons-with-floating-sidebar
Share buttons with extra features to sharing your website posts/pages on Facebook, Twitter, Instagram, Whatsapp, Pinterest etc.
Spice Social Share
spice-social-share
Effortlessly add social share buttons to your posts.
Social Sharing Plugin – Kiwi Developer Profile
9 plugins · 238K total installs
How We Detect Social Sharing Plugin – Kiwi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kiwi-social-share/assets/vendors/icomoon/style.css/wp-content/plugins/kiwi-social-share/assets/css/frontend.css/wp-content/plugins/kiwi-social-share/assets/css/frontend.min.css/wp-content/plugins/kiwi-social-share/assets/js/kiwi.js/wp-content/plugins/kiwi-social-share/assets/js/kiwi.min.js/wp-content/plugins/kiwi-social-share/assets/js/frontend.js/wp-content/plugins/kiwi-social-share/assets/js/frontend.min.js/wp-content/plugins/kiwi-social-share/assets/js/kiwi.js/wp-content/plugins/kiwi-social-share/assets/js/kiwi.min.js/wp-content/plugins/kiwi-social-share/assets/js/frontend.js/wp-content/plugins/kiwi-social-share/assets/js/frontend.min.jskiwi-social-share/assets/vendors/icomoon/style.css?ver=kiwi-social-share/assets/css/frontend.css?ver=kiwi-social-share/assets/css/frontend.min.css?ver=kiwi-social-share/assets/js/kiwi.js?ver=kiwi-social-share/assets/js/kiwi.min.js?ver=kiwi-social-share/assets/js/frontend.js?ver=kiwi-social-share/assets/js/frontend.min.js?ver=HTML / DOM Fingerprints
kiwi-social-sharedata-networkKiwi_Social_Sharekiwi_social_share_opts