
Social Sharing Plugin – Sassy Social Share Security & Risk Analysis
wordpress.org/plugins/sassy-social-shareThe Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
Is Social Sharing Plugin – Sassy Social Share Safe to Use in 2026?
Generally Safe
Score 94/100Social Sharing Plugin – Sassy Social Share has a strong security track record. Known vulnerabilities have been patched promptly.
The "sassy-social-share" plugin v3.3.79 exhibits a mixed security posture. While the static analysis shows no critical or high severity taint flows, and a reasonable percentage of SQL queries use prepared statements, there are significant concerns regarding its attack surface and vulnerability history. A large portion of its entry points, specifically 11 out of 13, lack authentication checks, making them prime targets for unauthorized access and potential exploitation. This, coupled with a history of 11 known CVEs, including high and medium severity issues like Open Redirect, XSS, and Deserialization vulnerabilities, suggests a pattern of past security weaknesses. Although there are currently no unpatched CVEs, the frequent discovery of past vulnerabilities indicates a potential for ongoing security challenges.
Despite the absence of dangerous functions and the presence of nonce and capability checks for some operations, the sheer number of unprotected AJAX handlers is a major concern. The vulnerability history, particularly the types of past issues (Open Redirect, XSS, Deserialization), points towards potential input validation and output escaping deficiencies that attackers might try to leverage, even if current static analysis doesn't highlight them as critical. The plugin demonstrates some good practices like using prepared statements for SQL and a decent percentage of output escaping, but these are overshadowed by the exposed attack surface and a concerning historical track record. A cautious approach is recommended when using this plugin due to the identified risks.
Key Concerns
- High number of unprotected AJAX handlers
- Significant vulnerability history (11 CVEs)
- Past high severity vulnerabilities
- Past medium severity vulnerabilities
- 25% of SQL queries not using prepared statements
- 68% of output escaping is not ideal
Social Sharing Plugin – Sassy Social Share Security Vulnerabilities
CVEs by Year
Severity Breakdown
11 total CVEs
Social Sharing Plugin – Sassy Social Share <= 3.3.75 - Reflected Cross-Site Scripting via 'heateor_mastodon_share' Parameter
Sassy Social Share <= 3.3.73 - Open Redirect
Social Sharing Plugin – Sassy Social Share <= 3.3.69 - Reflected Cross-Site Scripting via heateor_mastodon_share Parameter
Sassy Social Share <= 3.3.62 - Authenticated (Administrator+) Stored Cross-Site Scripting
Sassy Social Share <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Social Sharing Plugin – Sassy Social Share <= 3.3.58 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Sassy Social Share <= 3.3.56 - Authenticated (Contributor+) Stored Cross-Site Scripting
Sassy Social Share <= 3.3.44 - Authenticated (Contributor+) Stored Cross-Site Scripting
Sassy Social Share <= 3.3.3 - Reflected Cross-Site Scripting
Sassy Social Share <= 3.3.39 - Reflected Cross-Site Scripting
Sassy Social Share 3.3.23 - Object Injection
Social Sharing Plugin – Sassy Social Share Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Social Sharing Plugin – Sassy Social Share Attack Surface
AJAX Handlers 11
Shortcodes 2
WordPress Hooks 35
Maintenance & Trust
Social Sharing Plugin – Sassy Social Share Maintenance & Trust
Maintenance Signals
Community Trust
Social Sharing Plugin – Sassy Social Share Alternatives
Social Share, Social Login and Social Comments Plugin – Super Socializer
super-socializer
The unique Social Plugin to let you integrate Social Login, Social Share, Social Comments and Social Media follow at your website
Social Rocket – Social Sharing Plugin
social-rocket
Add fully-customizable social sharing buttons to your site. Easy to use and packed with many additional social networking features.
Social Media Share Buttons
fny-social-media-share-buttons
Share Buttons is the best sharing Plugin for WordPress based websites.
WP-Socialight
wp-socialight
WP-Socialight is a simple, lightweight social share plugin that will increase the interaction on your website.
Social Media by Lazy Cat Themes
social-media-by-lazy-cat-themes
This is a plugin that supports sharing of social media (with follower count) for the 10 most common social media providers.
Social Sharing Plugin – Sassy Social Share Developer Profile
6 plugins · 107K total installs
How We Detect Social Sharing Plugin – Sassy Social Share
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sassy-social-share/admin/css/sassy-social-share-admin.css/wp-content/plugins/sassy-social-share/admin/js/sassy-social-share-admin.js/wp-content/plugins/sassy-social-share/css/sassy-social-share.css/wp-content/plugins/sassy-social-share/js/sassy-social-share.js/wp-content/plugins/sassy-social-share/js/sassy-social-share.jssassy-social-share/admin/css/sassy-social-share-admin.css?ver=sassy-social-share/admin/js/sassy-social-share-admin.js?ver=sassy-social-share/css/sassy-social-share.css?ver=sassy-social-share/js/sassy-social-share.js?ver=HTML / DOM Fingerprints
heateor_sss_sharing_ulheateor_sss_horizontal_sharingheateor_sss_vertical_sharingheateor_sss_facebook_shareheateor_sss_twitter_shareheateor_sss_google_plus_shareheateor_sss_linkedin_shareheateor_sss_pinterest_share+3 moredata-heateor-sss-hrefdata-heateor-sss-no-countsdata-heateor-ss-offsetdata-heateor-sss-st-countdata-heateor-sss-share-urldata-heateor-sss-share-text+4 moreheateor_sss_share_countsheateor_sss_count_dataheateor_sss_custom_share_icons[Sassy_Social_Share][Sassy_Social_Share id=""]