
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic Security & Risk Analysis
wordpress.org/plugins/shareaholicBoost Audience Engagement with Award Winning Speed Optimized Social Tools: Share Buttons, Related Posts, Monetization & Google Analytics.
Is Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic Safe to Use in 2026?
Generally Safe
Score 91/100Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The Shareaholic plugin v9.7.13 exhibits a mixed security posture. While it demonstrates good practices such as having no dangerous functions, file operations, or bundled libraries, significant concerns arise from its extensive attack surface and insufficient authorization checks. The analysis reveals a substantial number of AJAX handlers (14 out of 14) that lack proper authentication, creating a wide entry point for potential attacks. Furthermore, only 32% of output escaping is properly handled, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities if untrusted data is not sufficiently sanitized before rendering. The plugin's vulnerability history, with 4 known medium-severity CVEs predominantly involving missing or incorrect authorization and XSS, reinforces these concerns. The recency of the last vulnerability (January 2024) suggests ongoing security challenges.
Despite these weaknesses, the plugin's use of prepared statements for a majority of its SQL queries and the presence of nonce and capability checks in some areas are positive signs. However, the critical issue of unprotected AJAX endpoints, coupled with the history of authorization and XSS flaws, presents a notable risk. The taint analysis shows one flow with unsanitized paths, which, while not classified as critical or high, is still a direct indicator of potential vulnerabilities. In conclusion, while Shareaholic v9.7.13 has some strengths, the large number of unprotected AJAX handlers and the historical pattern of authorization and XSS vulnerabilities necessitate caution.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- Medium severity vulnerabilities in history (4 total)
- Flow with unsanitized paths (taint analysis)
- Low percentage of SQL prepared statements
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Shareaholic <= 9.7.11 - Missing Authorization via accept_terms_of_service
Shareaholic <= 9.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic <= 9.7.5 - Information Disclosure
WordPress Social Sharing, Related Posts & Analytics – Shareaholic < 7.6.1.0 - Authenticated (Subscriber+) Cross-Site Scripting
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic Release Timeline
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic Attack Surface
AJAX Handlers 14
Shortcodes 1
WordPress Hooks 34
Scheduled Events 2
Maintenance & Trust
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic Maintenance & Trust
Maintenance Signals
Community Trust
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic Alternatives
My Social Reach
my-social-reach
Activate the plugin, and it will automatically add social sharing buttons at the end of the post content automatically.
Social Sharing 9
social-sharing-9
This is a customizable Social Sharing plugin for WordPress.
Social Sharing (by Danny)
dvk-social-sharing
Adds social sharing buttons for Twitter, Facebook and LinkedIn to your blog posts or pages.
WP Social Preview
wp-social-preview
Increase social media engagement by previewing and managing how your content will look on social media sites before sharing it!
Naked Social Share
naked-social-share
Simple, unstyled social share icons for theme designers.
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic Developer Profile
1 plugin · 20K total installs
How We Detect Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shareaholic/css/shareaholic.css/wp-content/plugins/shareaholic/js/shareaholic.min.js/wp-content/plugins/shareaholic/js/shareaholic.min.jsshareaholic/css/shareaholic.css?ver=shareaholic/js/shareaholic.min.js?ver=HTML / DOM Fingerprints
shareaholic-canvasshareaholic-share-buttonsshareaholic-related-posts<!-- Shareaholic --><!-- Shareaholic Related Posts --><!-- Shareaholic Share Buttons -->data-shareaholic-appdata-shareaholic-templatedata-shareaholic-hrefShareaholicShareaholicPublicShareaholicUtilitiesShareaholicAdmin/wp-json/shareaholic/v1/settings/wp-json/shareaholic/v1/content[shareaholic]