Nevamiss Auto Share Security & Risk Analysis

wordpress.org/plugins/nevamiss

This plugin allows site users to auto-share their site content to authorized social media accounts.

0 active installs v1.1.5 PHP 8.0+ WP 5.6+ Updated Jan 10, 2025
auto-postautopostrepostsocial-mediasocial-network
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Nevamiss Auto Share Safe to Use in 2026?

Generally Safe

Score 92/100

Nevamiss Auto Share has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "nevamiss" plugin v1.1.5 exhibits a generally good security posture with strong adherence to secure coding practices in several key areas. The complete absence of raw SQL queries and a high percentage of properly escaped output are positive indicators. Furthermore, the plugin's vulnerability history is clean, with no recorded CVEs, suggesting a well-maintained and secure codebase over time. The plugin also demonstrates good usage of nonces and capability checks, bolstering its defense against common attacks.

However, a significant concern arises from the presence of two AJAX handlers that lack authentication checks. This represents a direct and unprotected entry point into the plugin's functionality, potentially exposing it to unauthorized access and exploitation. While the absence of critical taint flows and dangerous functions is reassuring, this specific oversight in the AJAX handlers could be a vector for various attacks if not addressed.

In conclusion, while the "nevamiss" plugin has a strong foundation of secure coding, the two unprotected AJAX handlers are a critical weakness that needs immediate attention. Addressing these unprotected entry points would significantly enhance the plugin's overall security and mitigate potential risks.

Key Concerns

  • Unprotected AJAX handlers
Vulnerabilities
None known

Nevamiss Auto Share Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Nevamiss Auto Share Release Timeline

v1.1.5Current
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Nevamiss Auto Share Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
19 prepared
Unescaped Output
7
195 escaped
Nonce Checks
8
Capability Checks
2
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared19 total queries

Output Escaping

97% escaped202 total outputs
Attack Surface
2 unprotected

Nevamiss Auto Share Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_nevamiss_instant_sharesrc\services\class-services-module.php:117
authwp_ajax_nevamiss_sort_queue_postssrc\services\class-services-module.php:119
WordPress Hooks 31
actionplugins_loadednevamiss.php:97
actionadmin_enqueue_scriptssrc\application\class-application-module.php:54
actionadmin_post_facebooksrc\infrastructure\class-infrastructure-module.php:138
actionadmin_post_linkedinsrc\infrastructure\class-infrastructure-module.php:139
actionadmin_post_xsrc\infrastructure\class-infrastructure-module.php:140
actionadmin_post_instagramsrc\infrastructure\class-infrastructure-module.php:141
actionadmin_postsrc\infrastructure\class-infrastructure-module.php:142
actionadmin_menusrc\presentation\class-presentation-module.php:149
actionadd_meta_boxessrc\presentation\class-presentation-module.php:161
actionadmin_post_nevamiss_create_schedulesrc\presentation\class-presentation-module.php:165
actionadmin_post_nevamiss_settingssrc\presentation\class-presentation-module.php:170
actionadmin_post_nevamiss_schedules_delete_actionsrc\presentation\class-presentation-module.php:177
actionadmin_post_nevamiss_suggestion_postsrc\presentation\class-presentation-module.php:187
actionadmin_post_delete_allsrc\presentation\class-presentation-module.php:198
filterwp_kses_allowed_htmlsrc\presentation\class-presentation-module.php:205
actionnevamiss_schedule_create_tasks_completedsrc\services\class-services-module.php:73
actionnevamiss_schedule_task_completesrc\services\class-services-module.php:74
filtercron_schedulessrc\services\class-services-module.php:76
actionnevamiss_created_schedulesrc\services\class-services-module.php:77
actionnevamiss_after_schedule_updatedsrc\services\class-services-module.php:78
actionnevamiss_created_schedulesrc\services\class-services-module.php:80
actionnevamiss_after_schedule_updatedsrc\services\class-services-module.php:81
actionnevamiss_schedule_task_completesrc\services\class-services-module.php:82
actionnevamiss_schedule_task_completesrc\services\class-services-module.php:84
actionadmin_post_nevamiss_schedule_deletesrc\services\class-services-module.php:89
actionadmin_post_nevamiss_schedule_unschedulesrc\services\class-services-module.php:90
actionadmin_post_nevamiss_schedule_sharesrc\services\class-services-module.php:91
actiontransition_post_statussrc\services\class-services-module.php:93
actionadmin_post_nevamiss_network_accounts_deletesrc\services\class-services-module.php:95
actionadmin_post_nevamiss_stats_deletesrc\services\class-services-module.php:103
actionnevamiss_schedule_logsrc\services\class-services-module.php:126
Maintenance & Trust

Nevamiss Auto Share Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 10, 2025
PHP min version8.0
Downloads826

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Nevamiss Auto Share Developer Profile

Eliasu Abraman

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Nevamiss Auto Share

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nevamiss/css/style.css/wp-content/plugins/nevamiss/css/flatpickr.min.css/wp-content/plugins/nevamiss/build/main.js
Script Paths
/wp-content/plugins/nevamiss/build/main.js
Version Parameters
nevamiss/css/style.css?ver=nevamiss/css/flatpickr.min.css?ver=nevamiss/build/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
notice-error
Data Attributes
data-nonce="nevamiss_general_nonce"
JS Globals
nevamiss
FAQ

Frequently Asked Questions about Nevamiss Auto Share