
XING for WordPress Security & Risk Analysis
wordpress.org/plugins/share-on-xingEmbed the XING Share Button and the Follow Button on your Wordpress website without any hassle.
Is XING for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100XING for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'share-on-xing' plugin version 1.2.4 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the use of prepared statements for all SQL queries are strong indicators of secure coding practices. Furthermore, the plugin has a very small attack surface, with only one shortcode and no documented external requests or file operations, which reduces the potential for exploitation.
However, there are notable areas for improvement. The most significant concern is the lack of proper output escaping for a substantial portion (59%) of its output. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. Additionally, the plugin does not implement any nonce checks or capability checks, which are crucial for verifying user permissions and preventing cross-site request forgery (CSRF) attacks, especially if any of its entry points, including the shortcode, handle sensitive data or actions.
In conclusion, while the plugin benefits from a clean vulnerability history and solid SQL sanitization, the unescaped output and absence of nonce/capability checks present a significant risk. Addressing these specific code weaknesses would greatly enhance the plugin's overall security.
Key Concerns
- Significant unescaped output found
- Missing nonce checks
- Missing capability checks
XING for WordPress Security Vulnerabilities
XING for WordPress Release Timeline
XING for WordPress Code Analysis
Output Escaping
XING for WordPress Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
XING for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
XING for WordPress Alternatives
Кнопки социальных сетей
svensoft-social-share-buttons
Кнопки "Поделиться в социальных сетях"
All Social Share – Sticky & Floating Share Buttons for WordPress
all-social-share
Add lightweight, customizable social share buttons for Facebook, Twitter, LinkedIn, WhatsApp, Pinterest, Reddit, and more.
Unique Easy Share Posts
unique-easy-share-posts
The Best Social Share Posts plugin ever. The easiest way to share posts on social media links from admin side without refresh.
Pluginsify Social Share
pluginsify-social-share
Share post, pages, media, products on social media
SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher
wp-scheduled-posts
Automate your WordPress content scheduling with a visual calendar, auto/manual schedulers, missed‑post handler, social sharing options & templates.
XING for WordPress Developer Profile
1 plugin · 10 total installs
How We Detect XING for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/share-on-xing/static/css/styles.csshttps://www.xing-share.com/plugins/share.jshttps://www.xing-share.com/plugins/follow.jsHTML / DOM Fingerprints
xing-sharedata-xing-buttonwindow.xing_share_config[xing_share][xing_follow]