rtSocial Security & Risk Analysis

wordpress.org/plugins/rtsocial

This plugin uses non-blocking JavaScript to display social media sharing counters on posts/pages

50 active installs v2.2.4 PHP + WP 3.0+ Updated Jul 24, 2024
rtcampsharesharingsocialsocial-links
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is rtSocial Safe to Use in 2026?

Generally Safe

Score 92/100

rtSocial has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The rtsocial plugin v2.2.4 exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to security best practices, with no critical or high-severity issues identified in taint analysis. The plugin effectively utilizes prepared statements for all SQL queries, has a very high percentage of properly escaped output, and implements nonce and capability checks for its entry points, which is commendable. Furthermore, its vulnerability history is clean, with no recorded CVEs, suggesting a consistent commitment to security by its developers.

While the overall security is good, there are a couple of minor areas for attention. The presence of two AJAX handlers, even though protected by authentication and capability checks, represents a small attack surface. The single external HTTP request, while not inherently a vulnerability, is a common vector for supply chain attacks if the external service is compromised or malicious. However, given the absence of other significant risks, these are minor concerns. The plugin's strengths, particularly its robust use of security checks and lack of past vulnerabilities, significantly outweigh these minor points, indicating a generally secure and well-maintained plugin.

Key Concerns

  • AJAX handlers present
  • External HTTP request detected
Vulnerabilities
None known

rtSocial Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

rtSocial Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
46 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

96% escaped48 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
rtss_wp_get_shares (source.php:1232)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

rtSocial Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_rtss_wp_get_sharessource.php:1278
noprivwp_ajax_rtss_wp_get_sharessource.php:1279
WordPress Hooks 11
actionadmin_menusource.php:28
actionadmin_initsource.php:62
filterthe_contentsource.php:99
filterget_the_excerptsource.php:100
actionwp_enqueue_scriptssource.php:910
filterplugin_action_linkssource.php:978
actionadmin_initsource.php:1016
actionwp_footersource.php:1039
actionwp_headsource.php:1076
actionadd_meta_boxessource.php:1128
actionsave_postsource.php:1174
Maintenance & Trust

rtSocial Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 24, 2024
PHP min version
Downloads29K

Community Trust

Rating94/100
Number of ratings9
Active installs50
Developer Profile

rtSocial Developer Profile

rtCamp

19 plugins · 119K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
883 days
View full developer profile
Detection Fingerprints

How We Detect rtSocial

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rtsocial/css/rtsocial.css/wp-content/plugins/rtsocial/js/rtsocial.js
Script Paths
/wp-content/plugins/rtsocial/js/rtsocial.js
Version Parameters
rtsocial/style.css?ver=rtsocial/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
rtsocial-twitter-horizontal-buttonrtsocial-twitter-vertical-buttonrtsocial-twitter-icon-linkrtsocial-twitter-icon-buttonrtsocial-fb-like-darkrtsocial-fb-recommend-darkrtsocial-fb-recommend-lightrtsocial-fb-share+40 more
Data Attributes
data-fb-widthdata-fb-heightdata-fb-layoutdata-fb-actiondata-fb-colorschemedata-fb-kid-directed-site+6 more
JS Globals
rtsocial
FAQ

Frequently Asked Questions about rtSocial