
Social Icons Sticky Security & Risk Analysis
wordpress.org/plugins/share-social-mediaAdd social sharing icons to a post or page of your WordPress website and allow visitors to share your content on various social media sites.
Is Social Icons Sticky Safe to Use in 2026?
Generally Safe
Score 100/100Social Icons Sticky has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "share-social-media" plugin v1.7.6 exhibits a mixed security posture. On the positive side, the code demonstrates strong adherence to secure coding practices regarding database interactions and output handling. All SQL queries utilize prepared statements, and 100% of outputs are properly escaped, significantly mitigating risks of SQL injection and cross-site scripting (XSS) respectively. The absence of file operations and external HTTP requests further reduces the attack surface. However, a significant concern arises from the presence of three AJAX handlers, all of which lack proper authentication checks. While nonce and capability checks are present for these handlers, their effectiveness is compromised if not properly integrated with WordPress's authentication system, potentially allowing unauthenticated users to trigger these actions.
The taint analysis shows no critical or high-severity flows, and the vulnerability history is clean, with no recorded CVEs. This suggests that historically, the plugin has been relatively secure or has had its vulnerabilities promptly addressed. The presence of nonce and capability checks, despite the AJAX handler issues, indicates an intent to secure the code. However, the direct exposure of AJAX handlers without robust authentication mechanisms is a primary security risk. The lack of vulnerabilities historically is a positive sign, but it does not negate the current risks identified in the static analysis. The plugin has strengths in its data handling but a weakness in its AJAX endpoint security.
Key Concerns
- AJAX handlers without authentication
- AJAX handlers without proper auth checks
Social Icons Sticky Security Vulnerabilities
Social Icons Sticky Code Analysis
Output Escaping
Data Flow Analysis
Social Icons Sticky Attack Surface
AJAX Handlers 3
WordPress Hooks 5
Maintenance & Trust
Social Icons Sticky Maintenance & Trust
Maintenance Signals
Community Trust
Social Icons Sticky Alternatives
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Hubbub Lite – Fast, free social sharing and follow buttons
social-pug
Your content is worth sharing. Let's makes it easier!
Simple Social Media Share Buttons – Social Sharing for Everyone
simple-social-buttons
This Social Share Plugin adds advanced social media sharing buttons to your WordPress sites, such as Facebook, WhatsApp, X, LinkedIn, & Pinterest.
WP Socializer – Simple & Easy Social Media Share Icons
wp-socializer
Simple & easy plugin to add social media sharing icons, buttons like Facebook, Twitter, WhatsApp, Instagram & more
Easy Social Sharing
easy-social-sharing
Easy Social Sharing provides you with an easy way to display various popular social share buttons.
Social Icons Sticky Developer Profile
20 plugins · 20K total installs
How We Detect Social Icons Sticky
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/share-social-media/assets/css/stssm.min.css/wp-content/plugins/share-social-media/assets/js/stssm-admin.js/wp-content/plugins/share-social-media/assets/css/stssm-admin.cssassets/js/stssm-admin.jsshare-social-media/assets/css/stssm.min.css?ver=share-social-media/assets/js/stssm-admin.js?ver=share-social-media/assets/css/stssm-admin.css?ver=HTML / DOM Fingerprints
stssm-social-iconsstssm-content-social-iconsssm-fabssm-fasstssm-after-contentstssm-before-contentstssm-sticky-social-iconsaria-labeltabindexrolestssmadminurl