
SharePulse Security & Risk Analysis
wordpress.org/plugins/sharepulseSharePulse ranks in a widget your site's posts which have had the greatest share count, using Twitter, LinkedIn, Facebook and your comments.
Is SharePulse Safe to Use in 2026?
Generally Safe
Score 85/100SharePulse has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The SharePulse v3.2 plugin exhibits a mixed security posture. While it boasts a clean vulnerability history with no recorded CVEs, the static analysis reveals significant areas of concern. The plugin has a small attack surface, but one of its four AJAX handlers lacks any authentication checks, presenting a direct entry point for potential unauthorized actions. The code analysis further highlights a critical weakness: all SQL queries are executed without prepared statements, meaning there's a high risk of SQL injection vulnerabilities. Additionally, the plugin struggles with proper output escaping, with only 13% of outputs being correctly handled, increasing the likelihood of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, though limited in scope, did find two flows with unsanitized paths, indicating potential for vulnerabilities if these paths are exposed to user input.
While the absence of known CVEs and the lack of bundled libraries are positive indicators, the identified issues in authentication, SQL handling, and output escaping are substantial. The high percentage of unescaped output and the complete lack of prepared statements for SQL queries are particularly alarming. These fundamental security oversights, combined with an unprotected AJAX endpoint, suggest that while the plugin may not have a history of public exploits, it possesses inherent vulnerabilities that could be exploited. A cautious approach is recommended when using this plugin.
Key Concerns
- AJAX handler without auth checks
- SQL queries lack prepared statements
- Low percentage of properly escaped output
- Taint flows with unsanitized paths
SharePulse Security Vulnerabilities
SharePulse Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SharePulse Attack Surface
AJAX Handlers 4
WordPress Hooks 3
Maintenance & Trust
SharePulse Maintenance & Trust
Maintenance Signals
Community Trust
SharePulse Alternatives
Social Media Widget
social-media-widget
Adds links to all of your social media and sharing site profiles. Tons of icons come in 3 sizes, 4 icon styles, and 4 animations.
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)
miniorange-login-openid
Social Login with Discord, Facebook, Google, Twitter, LinkedIn and 40+ apps. Social login with social share and comments. Free, fast & easy! WooCo …
Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds
tagembed-widget
Collect & Embed Instagram Feed, Embed Facebook Feed, Embed YouTube Videos, Embed Twitter Feed, Google Reviews & 15+ Social Media Feed on website.
Social Media Auto Publish
social-media-auto-publish
Publish posts automatically to social media networks like Facebook, Twitter, Instagram, Tumblr, LinkedIn, Threads and Telegram.
Custom Share Buttons with Floating Sidebar
custom-share-buttons-with-floating-sidebar
Share buttons with extra features to sharing your website posts/pages on Facebook, Twitter, Instagram, Whatsapp, Pinterest etc.
SharePulse Developer Profile
6 plugins · 180 total installs
How We Detect SharePulse
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sharepulse/js/build-single.js/wp-content/plugins/sharepulse/js/rebuild.js/wp-content/plugins/sharepulse/css/rebuild.css/wp-content/plugins/sharepulse/js/build-single.js/wp-content/plugins/sharepulse/js/rebuild.jsHTML / DOM Fingerprints
SharePulse_widgetSharePulsedata-sp-noncesp_Ajax/wp-json/sharepulse/v1/settings