
Post Share Count Security & Risk Analysis
wordpress.org/plugins/post-share-countShow twitter and facebook share count.
Is Post Share Count Safe to Use in 2026?
Generally Safe
Score 85/100Post Share Count has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "post-share-count" plugin version 0.5.1 presents a mixed security posture. On one hand, the static analysis reveals a very small attack surface with zero identified entry points (AJAX, REST API, shortcodes, cron events) that are unprotected. This indicates a potentially strong focus on restricting access to plugin functionalities. Furthermore, there are no recorded vulnerabilities in its history, suggesting a stable and well-maintained codebase in the past.
However, significant concerns arise from the code signals. The plugin makes external HTTP requests, which can be a vector for various attacks if not handled securely. More critically, the single SQL query is not using prepared statements, creating a direct risk of SQL injection. Additionally, none of the outputs are properly escaped, posing a substantial risk for cross-site scripting (XSS) vulnerabilities. The complete absence of nonce and capability checks on any potential entry points further exacerbates these risks, as it implies that any user, regardless of their role or permissions, could potentially interact with and exploit these insecure functionalities.
In conclusion, while the plugin has a clean vulnerability history and a seemingly limited attack surface, the insecure handling of SQL queries and output escaping, coupled with the lack of crucial security checks, creates notable vulnerabilities. The external HTTP requests also warrant careful consideration. The absence of any recorded CVEs is a positive sign, but it does not negate the immediate risks identified in the static analysis of this specific version.
Key Concerns
- SQL queries not using prepared statements
- Outputs not properly escaped
- No nonce checks detected
- No capability checks detected
- External HTTP requests present
Post Share Count Security Vulnerabilities
Post Share Count Code Analysis
SQL Query Safety
Output Escaping
Post Share Count Attack Surface
Maintenance & Trust
Post Share Count Maintenance & Trust
Maintenance Signals
Community Trust
Post Share Count Alternatives
Wp Social Login and Register Social Counter
wp-social
Wp social lets you add social login, social counter, and social share buttons of different styles to your WordPress website.
Seed Social
seed-social
Minimal Social Sharing WordPress Plugin (Just Facebook, Twitter and Line)
Autopost for X (formerly Autoshare for Twitter)
autoshare-for-twitter
Automatically shares the post title or custom message and a link to the post to X/Twitter.
Custom Share Buttons with Floating Sidebar
custom-share-buttons-with-floating-sidebar
Share buttons with extra features to sharing your website posts/pages on Facebook, Twitter, Instagram, Whatsapp, Pinterest etc.
Spice Social Share
spice-social-share
Effortlessly add social share buttons to your posts.
Post Share Count Developer Profile
1 plugin · 10 total installs
How We Detect Post Share Count
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-share-count/css/style.css/wp-content/plugins/post-share-count/js/script.js/wp-content/plugins/post-share-count/js/script.jspost-share-count/css/style.css?ver=post-share-count/js/script.js?ver=HTML / DOM Fingerprints
share-linkgenericongenericon-sharegenericon-twittergenericon-facebookgenericon-pinterestgenericon-googleplusgenericon-linkedin