
Simple Share Follow Button Security & Risk Analysis
wordpress.org/plugins/simple-share-follow-buttonDisplays the Share button and Follow button.
Is Simple Share Follow Button Safe to Use in 2026?
Generally Safe
Score 100/100Simple Share Follow Button has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "simple-share-follow-button" plugin v1.10 presents a mixed security picture. On the positive side, the static analysis reveals a commendably small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed to users. Furthermore, all identified output is properly escaped, and there are no detected dangerous functions, file operations, or external HTTP requests, which are good security indicators. The taint analysis also shows no critical or high-severity issues, suggesting a lack of easily exploitable data flow vulnerabilities within the analyzed code paths.
However, there are significant areas of concern, primarily stemming from the vulnerability history and the approach to database interactions. The plugin has a documented history of a medium-severity Cross-Site Scripting (XSS) vulnerability, which indicates a past weakness in input sanitization or output escaping, even though the latest scan reports 100% proper escaping. The presence of a SQL query that does not use prepared statements is a notable risk, as it opens the door to SQL injection vulnerabilities, especially if user-supplied data is incorporated into that query without proper sanitization. The complete absence of nonce checks and capability checks across any entry points is also a critical oversight, leaving the plugin potentially vulnerable to CSRF attacks or unauthorized actions if any form of interaction were to be introduced in future versions or if undocumented entry points exist.
In conclusion, while the plugin has a clean slate regarding critical static analysis findings and an absence of currently unpatched CVEs, the historical XSS vulnerability and the use of raw SQL queries without prepared statements are significant red flags. The lack of robust authentication and authorization checks (nonces and capabilities) on its existing, albeit small, attack surface is a considerable weakness that could be exploited in conjunction with any future functional additions. Users should be aware of these potential risks, especially concerning data integrity and potential for unauthorized actions.
Key Concerns
- SQL queries without prepared statements
- Medium severity CVE in history
- No nonce checks
- No capability checks
Simple Share Follow Button Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Share Follow Button <= 1.03 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Simple Share Follow Button Release Timeline
Simple Share Follow Button Code Analysis
SQL Query Safety
Simple Share Follow Button Attack Surface
Maintenance & Trust
Simple Share Follow Button Maintenance & Trust
Maintenance Signals
Community Trust
Simple Share Follow Button Alternatives
Easy Social Icons
easy-social-icons
Upload your own social media icons or choose from font-awesome. Use widget|shortcode to place icons anywhere(sidebar, header, footer, page) in theme.
Superb Social Media Share Buttons and Follow Buttons
superb-social-share-and-follow-buttons
Social Media Share Buttons & Follow Buttons. Social Share Icons. 25+ Social networks. Icon & Button Shortcodes. Floating Sidebar.
BestWebSoft's Twitter
twitter-plugin
Add Twitter Follow, Tweet, Hashtag, and Mention buttons to WordPress posts and pages.
Follow Us Badges
wpsite-follow-us-badges
Follow Us Badges by 99 Robots showcases your Facebook, Twitter, LinkedIn. YouTube, Tumblr and other social media badges.
ShareThis Follow Buttons
sharethis-follow-buttons
Integrate ShareThis Follow Buttons seamlessly into your WordPress site.
Simple Share Follow Button Developer Profile
54 plugins · 56K total installs
How We Detect Simple Share Follow Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-share-follow-button/public/css/sf.css/wp-content/plugins/simple-share-follow-button/public/js/sf.js/wp-content/plugins/simple-share-follow-button/public/js/sf.jssimple-share-follow-button/public/css/sf.css?ver=simple-share-follow-button/public/js/sf.js?ver=HTML / DOM Fingerprints
sf-share-buttonsf-follow-buttonsf-buttonsdata-sf-titledata-sf-urldata-sf-imgdata-sf-descriptionsf_share_buttonssf_follow_buttons[simple_share][simple_follow]