
Shariff Wrapper Security & Risk Analysis
wordpress.org/plugins/shariffShariff provides share buttons that respect the privacy of your visitors and follow the General Data Protection Regulation (GDPR).
Is Shariff Wrapper Safe to Use in 2026?
Generally Safe
Score 86/100Shariff Wrapper has a strong security track record. Known vulnerabilities have been patched promptly.
The Shariff plugin v4.6.15 presents a mixed security posture. While it demonstrates some good practices like a reasonable number of capability checks and a lack of dangerous functions, several concerning areas warrant attention. The static analysis reveals a significant portion of SQL queries are not using prepared statements, which is a common vector for SQL injection vulnerabilities. Furthermore, the presence of unsanitized paths in taint analysis, even if not reaching critical severity, suggests a potential for path traversal issues. The plugin's history of six known CVEs, including one critical and five medium, is a significant red flag. The common vulnerability types highlight a recurring pattern of weaknesses in input sanitization and path handling, indicating a need for more robust security measures in these areas. The most recent vulnerability being in 2024 suggests that these issues are actively being discovered and exploited, and while currently unpatched CVEs are zero, the historical trend is worrying.
Despite the positive aspects, the historical vulnerability data and specific code signals like the lack of prepared statements for SQL queries are the most critical indicators of risk. The attack surface is relatively small, with only one unprotected entry point (a REST API route without permission callbacks), which is a good sign, but the historical trend of vulnerabilities, particularly those related to path traversal and XSS, demands a cautious approach. The plugin's strengths lie in its relatively limited attack surface and absence of inherently dangerous functions, but these are overshadowed by past security failures and ongoing coding concerns.
Key Concerns
- SQL queries not using prepared statements
- Unsanitized paths in taint flows
- REST API route without permission callback
- Historical critical CVE
- Historical medium CVEs (5)
- Output escaping at 56%
Shariff Wrapper Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Shariff Wrapper <= 4.6.13 - Unauthenticated Local File Inclusion
Shariff Wrapper <= 4.6.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Shariff Wrapper <= 4.6.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
Shariff Wrapper <= 4.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Shariff Wrapper <= 4.6.9 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
Shariff Wrapper <= 4.6.9 - Authenticated (Admin+) Stored Cross-Site Scripting
Shariff Wrapper Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Shariff Wrapper Attack Surface
REST API Routes 1
Shortcodes 2
WordPress Hooks 30
Scheduled Events 1
Maintenance & Trust
Shariff Wrapper Maintenance & Trust
Maintenance Signals
Community Trust
Shariff Wrapper Alternatives
GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law
gdpr-cookie-compliance
Cookie notice banner for GDPR, CCPA, EU cookie law, data protection and privacy regulations and other cookie law and consent notice requirements on yo …
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.
host-webfonts-local
OMGF automagically caches the Google Fonts used by your theme/plugins locally. No configuration (or brains) required!
Disable and Remove Google Fonts | GDPR & DSGVO friendly
disable-remove-google-fonts
Improve frontend performance by disabling Google Fonts. GDPR and DSGVO friendly.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Self-Hosted Google Fonts
selfhost-google-fonts
Automatically self-host all the Google Fonts on your site. Plug and play.
Shariff Wrapper Developer Profile
2 plugins · 40K total installs
How We Detect Shariff Wrapper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shariff/assets/css/admin.css/wp-content/plugins/shariff/assets/css/frontend.css/wp-content/plugins/shariff/assets/js/frontend.js/wp-content/plugins/shariff/assets/js/service.js/wp-content/plugins/shariff/assets/js/frontend.js/wp-content/plugins/shariff/assets/js/service.jsshariff/assets/css/admin.css?ver=shariff/assets/css/frontend.css?ver=shariff/assets/js/frontend.js?ver=shariff/assets/js/service.js?ver=HTML / DOM Fingerprints
shariff-wrappershariff-buttonsshariff-countshariff-social-button<!-- Begin Mailchimp Signup Form --><!-- End Mailchimp Signup Form --><!-- BEGIN: shariff-wrapper --><!-- END: shariff-wrapper -->data-urldata-servicesdata-themedata-orientationdata-backend-urlshariff_optionsshariff_services/wp-json/shariff/v1/share_counts[shariff]