
Shareboost Security & Risk Analysis
wordpress.org/plugins/shareboostIncrease social engagement.
Is Shareboost Safe to Use in 2026?
Generally Safe
Score 85/100Shareboost has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The shareboost plugin, version 1.0.0, exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the complete reliance on prepared statements for SQL queries is an excellent security practice, mitigating the risk of SQL injection vulnerabilities. The plugin also reports no known CVEs, which is a positive indicator of its current security track record.
However, several areas raise concerns. The low percentage of properly escaped output (9%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis revealed one flow with unsanitized paths, which, while not classified as critical or high, still represents a potential avenue for exploitation if that path is accessible and can be manipulated. The complete lack of nonce and capability checks, especially if there were any hidden entry points not captured by the static analysis, could leave the plugin vulnerable to CSRF or unauthorized actions.
In conclusion, while the plugin's limited attack surface and secure SQL practices are commendable, the significant issue with output escaping and the presence of an unsanitized path flow require immediate attention. The lack of historical vulnerabilities is a strength, but it does not negate the specific risks identified in the current code analysis.
Key Concerns
- Low output escaping percentage
- Unsanitized path flow
- No nonce checks
- No capability checks
Shareboost Security Vulnerabilities
Shareboost Code Analysis
Output Escaping
Data Flow Analysis
Shareboost Attack Surface
WordPress Hooks 6
Maintenance & Trust
Shareboost Maintenance & Trust
Maintenance Signals
Community Trust
Shareboost Alternatives
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Social Media Share Buttons & Social Sharing Icons
ultimate-social-media-icons
Share buttons and pop up share icons for social media sharing
Wp Social Login and Register Social Counter
wp-social
Wp social lets you add social login, social counter, and social share buttons of different styles to your WordPress website.
Shareboost Developer Profile
1 plugin · 10 total installs
How We Detect Shareboost
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shareboost-wordpress/css/admin.css/wp-content/plugins/shareboost-wordpress/js/admin.js/wp-content/plugins/shareboost-wordpress/css/public.csshttp://www.shareboost.com/shareboost.jsshareboost-wordpress-admin-stylesshareboost-wordpress-admin-scriptshareboost-wordpress-plugin-stylesshareboost-wordpress-plugin-scriptHTML / DOM Fingerprints
sbConfig