
Social Buttons Pack by BestWebSoft Security & Risk Analysis
wordpress.org/plugins/social-buttons-packAdd social media buttons and widgets to WordPress posts, pages and widgets. FB, Twitter, Pinterest, LinkedIn.
Is Social Buttons Pack by BestWebSoft Safe to Use in 2026?
Generally Safe
Score 100/100Social Buttons Pack by BestWebSoft has a strong security track record. Known vulnerabilities have been patched promptly.
The "social-buttons-pack" plugin v1.1.9 exhibits a generally good security posture based on the provided static analysis. A significant majority of SQL queries utilize prepared statements, and output escaping is exceptionally high (97%), indicating a strong effort to prevent common web vulnerabilities like SQL injection and XSS. The absence of unsanitized path flows in the taint analysis further strengthens this assessment, suggesting that file-based vulnerabilities are unlikely. The plugin also demonstrates a robust use of nonces and capability checks, especially considering the number of entry points analyzed.
However, the plugin's vulnerability history, with one past medium severity CVE related to Cross-Site Scripting (XSS) in 2017, warrants consideration. While currently unpatched CVEs are zero, this indicates a past weakness that, if not thoroughly addressed, could potentially re-emerge. The absence of documented issues in recent years is a positive sign, but vigilance is still recommended. The presence of file operations and external HTTP requests, while not flagged as immediately dangerous in the static analysis, represent potential attack vectors that require careful implementation and ongoing monitoring.
In conclusion, the plugin appears to have implemented several key security best practices, particularly regarding input sanitization and output escaping. The lack of critical or high-severity issues in the static analysis and recent vulnerability history are positive indicators. The primary area for attention is the historical XSS vulnerability, which, although resolved according to the data, highlights a potential area of concern that users should be aware of.
Key Concerns
- Past medium severity XSS vulnerability
Social Buttons Pack by BestWebSoft Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Social Buttons Pack by BestWebSoft < 1.1.1 - Reflected Cross-Site Scripting
Social Buttons Pack by BestWebSoft Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Social Buttons Pack by BestWebSoft Attack Surface
AJAX Handlers 2
Shortcodes 11
WordPress Hooks 67
Maintenance & Trust
Social Buttons Pack by BestWebSoft Maintenance & Trust
Maintenance Signals
Community Trust
Social Buttons Pack by BestWebSoft Alternatives
BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress
facebook-button-plugin
Add Facebook Follow, Like, and Share buttons to WordPress posts, pages, and widgets.
BestWebSoft's Twitter
twitter-plugin
Add Twitter Follow, Tweet, Hashtag, and Mention buttons to WordPress posts and pages.
Simple Share Buttons Adder
simple-share-buttons-adder
A simple plugin that enables you to add share buttons to all of your posts and/or pages.
Hubbub Lite – Fast, free social sharing and follow buttons
social-pug
Your content is worth sharing. Let's makes it easier!
ShareThis Share Buttons
sharethis-share-buttons
Grow your website traffic and engagement by enabling one-click sharing with the free ShareThis Share Buttons plugin. The plugin is free (no upgrades a …
Social Buttons Pack by BestWebSoft Developer Profile
32 plugins · 17K total installs
How We Detect Social Buttons Pack by BestWebSoft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-buttons-pack/css/admin_style.css/wp-content/plugins/social-buttons-pack/js/admin-script.js/wp-content/plugins/social-buttons-pack/js/admin-script.jssocial-buttons-pack/css/admin_style.css?ver=social-buttons-pack/js/admin-script.js?ver=HTML / DOM Fingerprints
sclbttns_settings_tabssclbttns_noticesclbttns_settingsdata-tabs-id='sclbttns_settings_tabs'sclbttns_var