
ShareThis Share Buttons Security & Risk Analysis
wordpress.org/plugins/sharethis-share-buttonsGrow your website traffic and engagement by enabling one-click sharing with the free ShareThis Share Buttons plugin. The plugin is free (no upgrades a …
Is ShareThis Share Buttons Safe to Use in 2026?
Generally Safe
Score 99/100ShareThis Share Buttons has a strong security track record. Known vulnerabilities have been patched promptly.
The "sharethis-share-buttons" plugin, version 2.3.7, exhibits a generally good security posture with strong adherence to secure coding practices. The static analysis reveals a commendable absence of directly exploitable entry points like AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks. Furthermore, all identified SQL queries are properly prepared, and there are no direct file operations, significantly reducing the risk of SQL injection or file manipulation vulnerabilities.
However, there are areas for improvement. The taint analysis identified two flows with unsanitized paths, which, while not flagged as critical or high severity in this analysis, represent potential avenues for vulnerabilities if exploited. The output escaping, while generally good at 74%, means that a significant portion of output (26%) is not properly escaped, creating a risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is involved.
The plugin's vulnerability history includes one medium severity CVE related to XSS, last patched on May 22, 2024. While this vulnerability is no longer unpatched, it highlights a historical susceptibility to XSS. The presence of only one medium severity CVE in the past, coupled with the current good practices in the code, suggests that the developers are responsive to security issues. Overall, the plugin is reasonably secure, but the remaining unsanitized paths and a notable percentage of unescaped output warrant attention for future development.
Key Concerns
- Unsanitized paths in taint flows
- Significant portion of output not escaped
- Past medium severity XSS vulnerability
ShareThis Share Buttons Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ShareThis Share Buttons <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via sharethis-inline-buttons Shortcode
ShareThis Share Buttons Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ShareThis Share Buttons Attack Surface
WordPress Hooks 1
Maintenance & Trust
ShareThis Share Buttons Maintenance & Trust
Maintenance Signals
Community Trust
ShareThis Share Buttons Alternatives
Simple Social Media Share Buttons – Social Sharing for Everyone
simple-social-buttons
This Social Share Plugin adds advanced social media sharing buttons to your WordPress sites, such as Facebook, WhatsApp, X, LinkedIn, & Pinterest.
ShareThis Follow Buttons
sharethis-follow-buttons
Integrate ShareThis Follow Buttons seamlessly into your WordPress site.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Simple Share Buttons Adder
simple-share-buttons-adder
A simple plugin that enables you to add share buttons to all of your posts and/or pages.
Hubbub Lite – Fast, free social sharing and follow buttons
social-pug
Your content is worth sharing. Let's makes it easier!
ShareThis Share Buttons Developer Profile
5 plugins · 21K total installs
How We Detect ShareThis Share Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sharethis-share-buttons/assets/css/admin.css/wp-content/plugins/sharethis-share-buttons/assets/js/admin.js/wp-content/plugins/sharethis-share-buttons/assets/js/frontend.js/wp-content/plugins/sharethis-share-buttons/assets/js/sharethis.js/wp-content/plugins/sharethis-share-buttons/assets/js/admin.js/wp-content/plugins/sharethis-share-buttons/assets/js/frontend.js/wp-content/plugins/sharethis-share-buttons/assets/js/sharethis.jssharethis-share-buttons/assets/css/admin.css?ver=sharethis-share-buttons/assets/js/admin.js?ver=sharethis-share-buttons/assets/js/frontend.js?ver=sharethis-share-buttons/assets/js/sharethis.js?ver=HTML / DOM Fingerprints
sharethis-inline-share-buttonsst_share_twitterst_share_whatsappst_share_facebookst_share_linkedinst_share_emailst_share_redditst_share_pinterest+41 moredata-sharethis-widgetdata-categorydata-networkdata-textdata-urldata-shortener+54 moreShareThisMinuteControl[sharethis]