
Shariff for WordPress Security & Risk Analysis
wordpress.org/plugins/shariff-sharingShariff enables website users to share their favorite content without compromising their privacy.
Is Shariff for WordPress Safe to Use in 2026?
Mostly Safe
Score 84/100Shariff for WordPress is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "shariff-sharing" v1.0.11 plugin presents a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and has no known currently unpatched vulnerabilities. Its attack surface, as measured by AJAX handlers, REST API routes, shortcodes, and cron events, is commendably zero, indicating a reduced potential for direct exploitation. However, significant concerns arise from the static analysis. The low percentage of properly escaped output (4%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data might be rendered directly into the web page without sufficient sanitization. The taint analysis also identified two flows with unsanitized paths, which, while not rated critical or high in this specific analysis, point to potential areas where malicious input could lead to unintended consequences, such as directory traversal or file manipulation if not handled with extreme care. The plugin's historical vulnerability data shows one past CVE, specifically an XSS vulnerability, reinforcing the concern about output escaping. While this past vulnerability is patched, the recurrence of XSS as a common type is a red flag. The bundling of Guzzle, a library, without version information, also carries a slight risk if it's an outdated or vulnerable version, though this is not explicitly detailed in the provided data.
Key Concerns
- Low percentage of properly escaped output
- Taint analysis shows unsanitized paths
- Bundled libraries (Guzzle) - potential outdated version
Shariff for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Shariff Sharing < 1.0.8 - Stored Cross-Site Scripting
Shariff for WordPress Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Shariff for WordPress Attack Surface
WordPress Hooks 8
Maintenance & Trust
Shariff for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Shariff for WordPress Alternatives
NextScripts: Social Networks Auto-Poster
social-networks-auto-poster-facebook-twitter-g
Automatically publishes blogposts to profiles/pages/groups on Twitter, Google+, Pinterest, LinkedIn, Blogger, Tumblr ... 22 more
Scriptless Social Sharing
scriptless-social-sharing
This plugin adds super simple social sharing buttons to your content.
WP Social Share
wp-social-share
Add Social Networks Share Button at Home, Category and Single Posts Pages.
Jumbo Share
jumbo-share
Add Mashable.com like social share bar to your web site.
Social Share
kento-social-share
Fancy Social share tool by https://pluginspoint.com
Shariff for WordPress Developer Profile
1 plugin · 1K total installs
How We Detect Shariff for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shariff-sharing/dep/shariff.complete.cssHTML / DOM Fingerprints
shariffdata-twitter-viadata-titledata-info-urldata-backend-urldata-tempdata-ttl+7 more/wp-content/plugins/shariff-sharing/backend/index.php<div class="shariff"