
Sharedaddy More Control Security & Risk Analysis
wordpress.org/plugins/sharedaddy-more-controlAdds more options to control where Sharedaddy is being displayed.
Is Sharedaddy More Control Safe to Use in 2026?
Generally Safe
Score 85/100Sharedaddy More Control has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sharedaddy-more-control" plugin version 0.3 exhibits a seemingly strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface points like AJAX handlers, REST API routes, or shortcodes, coupled with the complete lack of dangerous functions and file operations, suggests a very limited exposure. Furthermore, all SQL queries are reported to use prepared statements, which is a crucial security practice. The plugin also has no recorded vulnerability history, indicating a stable and secure past.
However, a significant concern arises from the static analysis revealing that 100% of its total outputs are not properly escaped. This is a critical weakness, as unescaped output can lead to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious code into the site's front-end. The absence of any identified taint flows might be misleading if the analysis scope was limited or if the vulnerabilities stem from subtle input manipulations that weren't flagged. The lack of nonce and capability checks also contribute to the potential for unauthorized actions if any unanalyzed entry points were to exist or if future versions introduced them.
In conclusion, while the plugin demonstrates good practices in areas like SQL handling and attack surface minimization, the universal lack of output escaping is a severe oversight that exposes the site to XSS attacks. The clean vulnerability history is a positive sign, but it does not negate the immediate risk posed by the unescaped output. The absence of checks on capabilities and nonces further adds to the potential risk profile, especially if new functionalities are added in the future. Users should be aware of the XSS risk and consider this plugin's security implications carefully.
Key Concerns
- 100% of outputs not properly escaped
- 0 nonce checks
- 0 capability checks
Sharedaddy More Control Security Vulnerabilities
Sharedaddy More Control Release Timeline
Sharedaddy More Control Code Analysis
Output Escaping
Sharedaddy More Control Attack Surface
WordPress Hooks 4
Maintenance & Trust
Sharedaddy More Control Maintenance & Trust
Maintenance Signals
Community Trust
Sharedaddy More Control Alternatives
Post Types Order
post-types-order
Sort posts and custom post type objects using a drag-and-drop, sortable JavaScript AJAX interface, or through the default WordPress dashboard
Gravity Forms + Custom Post Types
gravity-forms-custom-post-types
Map your Gravity-Forms-generated posts to a custom post type and/or custom taxonomies.
JSM Show Post Metadata
jsm-show-post-meta
Show post metadata (aka custom fields) in a metabox when editing posts / pages - a great tool for debugging issues with post metadata.
MB Custom Post Types & Custom Taxonomies
mb-custom-post-type
Create and manage custom post types and custom taxonomies with an easy-to-use UI in WordPress.
No Page Comment
no-page-comment
An admin interface to control the default comment and trackback settings on new posts, pages and custom post types.
Sharedaddy More Control Developer Profile
10 plugins · 510 total installs
How We Detect Sharedaddy More Control
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sharedaddy-more-control/sharedaddy-more-control.php