
Minimal Share Buttons Security & Risk Analysis
wordpress.org/plugins/minimal-share-buttonsA social share plugin that doesn't spy on users and doesn't slow down your site.
Is Minimal Share Buttons Safe to Use in 2026?
Generally Safe
Score 99/100Minimal Share Buttons has a strong security track record. Known vulnerabilities have been patched promptly.
The minimal-share-buttons plugin v1.8.0 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a strong indicator of secure coding practices. The high percentage of properly escaped output (90%) further contributes to a positive security outlook, minimizing the risk of cross-site scripting vulnerabilities originating from the plugin's core functions.
However, there are a few areas that warrant attention. The static analysis did not cover taint flows, meaning potential vulnerabilities related to unsanitized input that could lead to more severe issues might have been missed. While the number of entry points is low, the existence of a shortcode with no explicit capability checks or nonce verification on its execution path presents a potential, albeit minor, risk if that shortcode handles user-supplied data. The plugin has a history of a medium-severity Cross-Site Scripting vulnerability, which, although patched, indicates that such vulnerabilities have been present in the past and a certain level of diligence is required.
Overall, the plugin appears to be well-maintained and follows many security best practices. The primary areas for improvement would be to ensure taint analysis is comprehensive in future reviews and to implement robust authorization and nonce checks on any shortcodes that interact with user input. The historical XSS vulnerability, while resolved, emphasizes the need for ongoing vigilance and thorough auditing, especially for plugins that handle content generation and user interaction.
Key Concerns
- Shortcode without explicit permission checks
- No taint analysis performed
- Historical medium severity XSS vulnerability
Minimal Share Buttons Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Minimal Share Buttons <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Parameter
Minimal Share Buttons Code Analysis
Output Escaping
Minimal Share Buttons Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Minimal Share Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Minimal Share Buttons Alternatives
SGS Social Sharing Buttons
sgs-social-sharing-buttons
SGS Social Sharing Buttons is a lightweight plugin that adds fixed social media sharing buttons to your WordPress site.
Jackshare Social Sharing
jackshare
Super simple Social media sharing buttons with minimal design and lightning fast performance.
My Social Media
my-social-media
A simple and nice plugin to display the administrator information where admin enter their social media information like Facebook, Twitter, LinkedIn, Y …
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds
facebook-pagelike-widget
Floating Social Media Icons, Sticky Share Buttons, Facebook Feeds, & Popup builder. Also, create Call, Email, SMS, & Contact buttons to increa …
Minimal Share Buttons Developer Profile
1 plugin · 100 total installs
How We Detect Minimal Share Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/minimal-share-buttons/assets/js/svg4everybody.legacy.min.js/wp-content/plugins/minimal-share-buttons/assets/js/minimal-share-buttons.js/wp-content/plugins/minimal-share-buttons/assets/js/msb.min.js/wp-content/plugins/minimal-share-buttons/assets/css/minimal-share-buttons.cssassets/js/svg4everybody.legacy.min.jsassets/js/minimal-share-buttons.jsassets/js/msb.min.jsminimal-share-buttons/assets/css/minimal-share-buttons.css?ver=minimal-share-buttons/assets/js/svg4everybody.legacy.min.js?ver=minimal-share-buttons/assets/js/minimal-share-buttons.js?ver=minimal-share-buttons/assets/js/msb.min.js?ver=HTML / DOM Fingerprints
msb-containericonaria-hidden[msb_share]