
Sharing Plus – Social Sharing Icons Security & Risk Analysis
wordpress.org/plugins/sharing-plusSharing Plus adds an advanced set of social media sharing buttons to your WordPress sites, such as: Google+, Facebook, WhatsApp, Viber, Twitter, Reddi …
Is Sharing Plus – Social Sharing Icons Safe to Use in 2026?
Generally Safe
Score 85/100Sharing Plus – Social Sharing Icons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sharing-plus" v1.0.1 plugin exhibits a mixed security posture. While it demonstrates good practices in handling SQL queries using prepared statements and a relatively high percentage of properly escaped outputs, significant concerns arise from its attack surface and taint analysis.
A major weakness lies in the presence of 6 unprotected AJAX handlers, representing a substantial portion of its entry points. This opens the door for unauthenticated users to potentially interact with sensitive functionalities. Furthermore, the taint analysis reveals 2 high-severity flows with unsanitized paths, indicating a risk of data being processed without adequate validation or sanitization, which could lead to various vulnerabilities depending on the context.
The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator of past security diligence. However, the static analysis findings, particularly the unprotected AJAX handlers and high-severity taint flows, suggest that current security practices may not be sufficient to prevent future vulnerabilities. The presence of `create_function` is also a concern, as it can be a source of security issues if not handled with extreme care. In conclusion, while the plugin has a clean history and some good coding habits, the identified attack surface vulnerabilities and taint issues require immediate attention to strengthen its overall security.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized paths
- Dangerous function: create_function
- Partially unescaped output
Sharing Plus – Social Sharing Icons Security Vulnerabilities
Sharing Plus – Social Sharing Icons Release Timeline
Sharing Plus – Social Sharing Icons Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Sharing Plus – Social Sharing Icons Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 31
Maintenance & Trust
Sharing Plus – Social Sharing Icons Maintenance & Trust
Maintenance Signals
Community Trust
Sharing Plus – Social Sharing Icons Alternatives
Hubbub Lite – Fast, free social sharing and follow buttons
social-pug
Your content is worth sharing. Let's makes it easier!
Simple Social Media Share Buttons – Social Sharing for Everyone
simple-social-buttons
This Social Share Plugin adds advanced social media sharing buttons to your WordPress sites, such as Facebook, WhatsApp, X, LinkedIn, & Pinterest.
Custom Share Buttons with Floating Sidebar
custom-share-buttons-with-floating-sidebar
Share buttons with extra features to sharing your website posts/pages on Facebook, Twitter, Instagram, Whatsapp, Pinterest etc.
Spice Social Share
spice-social-share
Effortlessly add social share buttons to your posts.
Cresta Social Share Counter
cresta-social-share-counter
Share your posts and pages quickly and easily with Cresta Social Share Counter and show share counts.
Sharing Plus – Social Sharing Icons Developer Profile
3 plugins · 810 total installs
How We Detect Sharing Plus – Social Sharing Icons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sharing-plus/css/style.css/wp-content/plugins/sharing-plus/js/sharing-plus.js/wp-content/plugins/sharing-plus/js/script.js/wp-content/plugins/sharing-plus/admin/css/admin.css/wp-content/plugins/sharing-plus/js/sharing-plus.js/wp-content/plugins/sharing-plus/js/script.jssharing-plus/css/style.css?ver=sharing-plus/js/sharing-plus.js?ver=sharing-plus/js/script.js?ver=HTML / DOM Fingerprints
sharing_plus_inline_wrapper<!-- Sharing Plus --><!-- Sharing Plus End -->data-sharing-plus-post-idsharing_plus_ajax_object[SHARING_PLUS]