Posts shared counter for social website Security & Risk Analysis

wordpress.org/plugins/posts-shared-counter-for-social-website

Automatically generate the Post (posts) social media website like and shared counter. - facebook, twitter, linkedin, google, pinterest, stumbleupon -

10 active installs v2.3 PHP + WP 3.1+ Updated Dec 23, 2014
counterpostposts-shared-countersharedtracker
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Posts shared counter for social website Safe to Use in 2026?

Generally Safe

Score 85/100

Posts shared counter for social website has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "posts-shared-counter-for-social-website" plugin version 2.3 exhibits several concerning security practices despite a clean vulnerability history. The plugin exposes two AJAX handlers directly to the public without any authentication or capability checks, creating a significant attack surface for unauthorized actions. Furthermore, the presence of the `unserialize` function, coupled with taint analysis revealing two high-severity flows with unsanitized paths, strongly suggests a high risk of Remote Code Execution (RCE) or other serious vulnerabilities. While the plugin has no recorded CVEs, this historical absence should not be interpreted as current safety, especially given the static analysis findings. The low percentage of properly escaped output further exacerbates the risk, potentially leading to Cross-Site Scripting (XSS) vulnerabilities. The plugin's overall security posture is weak due to these fundamental flaws in handling user input and authentication, overshadowing the positive aspects like a moderate use of prepared statements.

Key Concerns

  • Unprotected AJAX handlers
  • High severity taint flows
  • Dangerous function unserialize
  • Low output escaping percentage
  • Missing nonce checks on AJAX
Vulnerabilities
None known

Posts shared counter for social website Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Posts shared counter for social website Code Analysis

Dangerous Functions
3
Raw SQL Queries
6
4 prepared
Unescaped Output
63
25 escaped
Nonce Checks
1
Capability Checks
3
File Operations
1
External Requests
2
Bundled Libraries
0

Dangerous Functions Found

unserialize$toplam_paylasim_kpst = unserialize($guncelsonuclar);class.kpst-counter-widget.php:186
unserialize$toplam_paylasim_kpst = unserialize(get_site_option($cachecek_ismi));class.kpst-counter-widget.php:190
unserialize$yedekson = unserialize(get_site_option($cachecek_ismi));class.kpst-counter-widget.php:471

SQL Query Safety

40% prepared10 total queries

Output Escaping

28% escaped88 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
kuaza_social_icerikleriguncelle (kuaza-post-shared-counter.php:1664)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Posts shared counter for social website Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_kpst_social_counter_ajaxkuaza-post-shared-counter.php:555
noprivwp_ajax_kpst_social_counter_ajaxkuaza-post-shared-counter.php:556
WordPress Hooks 15
actionwidgets_initclass.kpst-counter-widget.php:508
actionadd_meta_boxeskuaza-post-shared-counter.php:38
actionsave_postkuaza-post-shared-counter.php:39
filtermanage_posts_columnskuaza-post-shared-counter.php:138
actionmanage_posts_custom_columnkuaza-post-shared-counter.php:139
actionplugins_loadedkuaza-post-shared-counter.php:154
actionadmin_menukuaza-post-shared-counter.php:164
actionwp_headkuaza-post-shared-counter.php:174
actionadmin_headkuaza-post-shared-counter.php:175
actionwp_enqueue_scriptskuaza-post-shared-counter.php:537
filterthe_contentkuaza-post-shared-counter.php:596
actionpublish_postkuaza-post-shared-counter.php:1755
actionedit_postkuaza-post-shared-counter.php:1756
actionadmin_initkuaza-post-shared-counter.php:1762
actiondelete_postkuaza-post-shared-counter.php:1765
Maintenance & Trust

Posts shared counter for social website Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedDec 23, 2014
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Posts shared counter for social website Developer Profile

maffay

5 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Posts shared counter for social website

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
paylasimcevrebtnbtn-toplampaylasimbtn-pinterestbtn-twitterx
Data Attributes
kpst_inner_custom_box_noncekpst_konuda_goster
FAQ

Frequently Asked Questions about Posts shared counter for social website