Shariff for WordPress Security & Risk Analysis

wordpress.org/plugins/shariff-sharing

Shariff enables website users to share their favorite content without compromising their privacy.

1K active installs v1.0.11 PHP + WP 3.0+ Updated Nov 28, 2017
networknetworksprivacysharingsocial
84
B · Generally Safe
CVEs total1
Unpatched0
Last CVEDec 5, 2014
Safety Verdict

Is Shariff for WordPress Safe to Use in 2026?

Mostly Safe

Score 84/100

Shariff for WordPress is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVELast CVE: Dec 5, 2014Updated 8yr ago
Risk Assessment

The "shariff-sharing" v1.0.11 plugin presents a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and has no known currently unpatched vulnerabilities. Its attack surface, as measured by AJAX handlers, REST API routes, shortcodes, and cron events, is commendably zero, indicating a reduced potential for direct exploitation. However, significant concerns arise from the static analysis. The low percentage of properly escaped output (4%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data might be rendered directly into the web page without sufficient sanitization. The taint analysis also identified two flows with unsanitized paths, which, while not rated critical or high in this specific analysis, point to potential areas where malicious input could lead to unintended consequences, such as directory traversal or file manipulation if not handled with extreme care. The plugin's historical vulnerability data shows one past CVE, specifically an XSS vulnerability, reinforcing the concern about output escaping. While this past vulnerability is patched, the recurrence of XSS as a common type is a red flag. The bundling of Guzzle, a library, without version information, also carries a slight risk if it's an outdated or vulnerable version, though this is not explicitly detailed in the provided data.

Key Concerns

  • Low percentage of properly escaped output
  • Taint analysis shows unsanitized paths
  • Bundled libraries (Guzzle) - potential outdated version
Vulnerabilities
1

Shariff for WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2014
2014
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

WF-11f883d2-c183-4cc9-a330-6c50610a5c39-shariff-sharinghigh · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Shariff Sharing < 1.0.8 - Stored Cross-Site Scripting

Dec 5, 2014 Patched in 1.0.8 (3336d)
Code Analysis
Analyzed Mar 16, 2026

Shariff for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
1 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

4% escaped23 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
run (backend\index.php:8)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Shariff for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionsave_postshariff-wp.php:313
actionadmin_initshariff-wp.php:331
actionadmin_menushariff-wp.php:332
actionadmin_initshariff-wp.php:333
actioninitshariff-wp.php:334
actionwp_enqueue_scriptsshariff-wp.php:335
actionwp_footershariff-wp.php:336
filterthe_contentshariff-wp.php:337
Maintenance & Trust

Shariff for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedNov 28, 2017
PHP min version
Downloads31K

Community Trust

Rating82/100
Number of ratings18
Active installs1K
Developer Profile

Shariff for WordPress Developer Profile

yanniks

1 plugin · 1K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
3336 days
View full developer profile
Detection Fingerprints

How We Detect Shariff for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shariff-sharing/dep/shariff.complete.css

HTML / DOM Fingerprints

CSS Classes
shariff
Data Attributes
data-twitter-viadata-titledata-info-urldata-backend-urldata-tempdata-ttl+7 more
REST Endpoints
/wp-content/plugins/shariff-sharing/backend/index.php
Shortcode Output
<div class="shariff"
FAQ

Frequently Asked Questions about Shariff for WordPress