Share on Pixelfed Security & Risk Analysis
wordpress.org/plugins/share-on-pixelfedAutomatically share WordPress (image) posts on Pixelfed.
Is Share on Pixelfed Safe to Use in 2026?
Generally Safe
Score 100/100Share on Pixelfed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'share-on-pixelfed' plugin version 0.9.0 exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent adherence to security best practices by employing prepared statements for all SQL queries, ensuring 100% proper output escaping, and implementing nonce and capability checks on all identified entry points. The absence of dangerous functions and critical/high severity taint flows further bolsters its security. The plugin also has no recorded vulnerability history, indicating a consistent track record of security.
However, a minor concern arises from the presence of external HTTP requests. While not inherently a vulnerability, such requests can introduce risks if not properly validated or if they communicate with untrusted endpoints, especially if any data is being transmitted unsanitized. The single file operation, without further context, is also a potential area to monitor, though it's unlikely to be a significant risk given the other strong security signals.
In conclusion, 'share-on-pixelfed' v0.9.0 appears to be a secure plugin with robust protections in place. The minimal potential risks associated with external HTTP requests and file operations are outweighed by the strong implementation of fundamental security controls and the clean vulnerability history.
Key Concerns
- External HTTP requests present a potential attack vector
Share on Pixelfed Security Vulnerabilities
Share on Pixelfed Code Analysis
SQL Query Safety
Output Escaping
Share on Pixelfed Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 18
Scheduled Events 2
Maintenance & Trust
Share on Pixelfed Maintenance & Trust
Maintenance Signals
Community Trust
Share on Pixelfed Alternatives
Share on Mastodon
share-on-mastodon
Automatically share WordPress posts on Mastodon.
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
themeisle-companion
Add modules like share buttons, header & footer scripts, disable comments, reading progress bar, custom fonts, custom login page & more in one plugin.
Share on Pixelfed Developer Profile
4 plugins · 1K total installs
How We Detect Share on Pixelfed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/share-on-pixelfed/assets/block-editor.jsHTML / DOM Fingerprints
/wp-json/share-on-pixelfed/v1/url