Simple Social – Sharing Widgets & Icons Updated Security & Risk Analysis
wordpress.org/plugins/simple-social-sharing-widgets-icons-updatedAdds a set of cool icons and widgets at the end of your post for your readers to share.
Is Simple Social – Sharing Widgets & Icons Updated Safe to Use in 2026?
Generally Safe
Score 85/100Simple Social – Sharing Widgets & Icons Updated has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simple-social-sharing-widgets-icons-updated" plugin v0.3.6 currently exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code analysis shows no dangerous functions, no raw SQL queries (all use prepared statements), and no external HTTP requests, which are all positive indicators. Taint analysis also reveals no vulnerabilities.
However, a critical concern arises from the complete lack of output escaping. With 7 total outputs analyzed and 0% properly escaped, this presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through the plugin's outputs, leading to unauthorized actions on behalf of users or the theft of sensitive information. Additionally, the complete absence of nonce and capability checks across all entry points, though currently limited in number, means that any future additions to the attack surface without proper authorization checks could be exploited. The plugin's vulnerability history being clean is positive but doesn't negate the risks identified in the static analysis.
In conclusion, while the plugin has strengths in its limited attack surface and use of prepared statements, the critical lack of output escaping and absence of authorization checks represent significant security weaknesses that require immediate attention.
Key Concerns
- 0% output escaping on 7 outputs
- 0 capability checks on entry points
- 0 nonce checks on entry points
Simple Social – Sharing Widgets & Icons Updated Security Vulnerabilities
Simple Social – Sharing Widgets & Icons Updated Code Analysis
Output Escaping
Simple Social – Sharing Widgets & Icons Updated Attack Surface
WordPress Hooks 4
Maintenance & Trust
Simple Social – Sharing Widgets & Icons Updated Maintenance & Trust
Maintenance Signals
Community Trust
Simple Social – Sharing Widgets & Icons Updated Alternatives
El club de la Noticia
el-club-de-la-noticia
English
2-Klicks-Button – Socialshareprivacy Plugin
2-klicks-button-socialshareprivacy-plugin
Wordpress-Plugin Umsetzung des 2-Klick-Button Scripts von heise.de Datenschutz freundliche Social-Media-Einbindung von Facebook, Twitter und Google+.
WP-Social-Share-Privacy
wp-social-share-privacy-plugin
Wordpress-Plugin Umsetzung des jQuery Plug-In socialshareprivacy von heise.de
Sociable RE
sociable-re
Добавляет кнопки для публикации ссылок в соц. сетях на страницы блога.
Sociable Zyblog Edition
sociable-zyblog-edition
Automatically add links on your posts to popular social bookmarking sites.
Simple Social – Sharing Widgets & Icons Updated Developer Profile
1 plugin · 100 total installs
How We Detect Simple Social – Sharing Widgets & Icons Updated
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-social-sharing-widgets-icons-updated/icons_32//wp-content/plugins/simple-social-sharing-widgets-icons-updated/icons_48//wp-content/plugins/simple-social-sharing-widgets-icons-updated/icons_64/http://platform.twitter.com/widgets.jshttps://apis.google.com/js/plusone.jsHTML / DOM Fingerprints
simplesocial-boxsimplesocial-titlesimplesocialsimplesocial-cleardata-urldata-textdata-countsimplesocial