
Share by Email Security & Risk Analysis
wordpress.org/plugins/share-by-emailLightweight plugin that gives your readers an easy way to share your content via their email client. A classic Share via Email link.
Is Share by Email Safe to Use in 2026?
Generally Safe
Score 100/100Share by Email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'share-by-email' plugin v1.0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, exclusively employing prepared statements for SQL queries, and making no external HTTP requests. The presence of nonce checks (though only two) is also a positive indicator. However, several areas raise concern. A significant weakness is the presence of one unprotected REST API route, which represents a direct entry point for potential exploitation without proper authorization. Furthermore, the plugin struggles with output escaping, with less than half of its outputs being properly sanitized. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully.
The plugin's vulnerability history is currently clean, with no recorded CVEs. This suggests that either the plugin has been well-maintained, or it has not been a target for sophisticated attacks, or its vulnerabilities have not yet been publicly disclosed. The absence of taint analysis flows is noted, meaning that specific data flow vulnerabilities could not be identified by this method. Overall, while the plugin avoids some common pitfalls, the unprotected REST API endpoint and the high percentage of unescaped output are significant weaknesses that require attention.
Key Concerns
- Unprotected REST API route
- Low percentage of properly escaped output
Share by Email Security Vulnerabilities
Share by Email Code Analysis
Output Escaping
Share by Email Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Share by Email Maintenance & Trust
Maintenance Signals
Community Trust
Share by Email Alternatives
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)
wpo365-login
WordPress + Microsoft Entra | Ext. ID | B2C | M365 Integration for your Digital Workplace. For SSO, Mail, Roles, Access, Profiles, SharePoint, PowerBI …
Sharedaddy
sharedaddy
Future upgrades to Sharedaddy plugin will only be available in Jetpack.
Recommend to a friend
recommend-a-friend
Plugin that add a share to friends jQuery Lightbox to your pages or posts. Users will be able to share your content using 2 ways :
DBWD Send Link to Page
dbwd-send-link
Share your website with others.
Recommend by mail widget
recommend-by-mail-widget
Recommend the site or the current page to a friend by mail.
Share by Email Developer Profile
4 plugins · 750 total installs
How We Detect Share by Email
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/share-by-email/admin/css/share-by-email-admin.css/wp-content/plugins/share-by-email/admin/js/share-by-email-admin.js/wp-content/plugins/share-by-email/admin/js/share-by-email-admin.jsshare-by-email/admin/css/share-by-email-admin.css?ver=share-by-email/admin/js/share-by-email-admin.js?ver=