Social Buttons Pack by BestWebSoft Security & Risk Analysis

wordpress.org/plugins/social-buttons-pack

Add social media buttons and widgets to WordPress posts, pages and widgets. FB, Twitter, Pinterest, LinkedIn.

200 active installs v1.1.9 PHP + WP 5.6+ Updated Jun 10, 2025
facebook-buttonsgoogle-buttonslinkedin-buttonssocial-buttonstwitter-buttons
100
A · Safe
CVEs total1
Unpatched0
Last CVEApr 17, 2017
Safety Verdict

Is Social Buttons Pack by BestWebSoft Safe to Use in 2026?

Generally Safe

Score 100/100

Social Buttons Pack by BestWebSoft has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 17, 2017Updated 9mo ago
Risk Assessment

The "social-buttons-pack" plugin v1.1.9 exhibits a generally good security posture based on the provided static analysis. A significant majority of SQL queries utilize prepared statements, and output escaping is exceptionally high (97%), indicating a strong effort to prevent common web vulnerabilities like SQL injection and XSS. The absence of unsanitized path flows in the taint analysis further strengthens this assessment, suggesting that file-based vulnerabilities are unlikely. The plugin also demonstrates a robust use of nonces and capability checks, especially considering the number of entry points analyzed.

However, the plugin's vulnerability history, with one past medium severity CVE related to Cross-Site Scripting (XSS) in 2017, warrants consideration. While currently unpatched CVEs are zero, this indicates a past weakness that, if not thoroughly addressed, could potentially re-emerge. The absence of documented issues in recent years is a positive sign, but vigilance is still recommended. The presence of file operations and external HTTP requests, while not flagged as immediately dangerous in the static analysis, represent potential attack vectors that require careful implementation and ongoing monitoring.

In conclusion, the plugin appears to have implemented several key security best practices, particularly regarding input sanitization and output escaping. The lack of critical or high-severity issues in the static analysis and recent vulnerability history are positive indicators. The primary area for attention is the historical XSS vulnerability, which, although resolved according to the data, highlights a potential area of concern that users should be aware of.

Key Concerns

  • Past medium severity XSS vulnerability
Vulnerabilities
1

Social Buttons Pack by BestWebSoft Security Vulnerabilities

CVEs by Year

1 CVE in 2017
2017
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2017-18500medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Social Buttons Pack by BestWebSoft < 1.1.1 - Reflected Cross-Site Scripting

Apr 17, 2017 Patched in 1.1.1 (2472d)
Code Analysis
Analyzed Mar 16, 2026

Social Buttons Pack by BestWebSoft Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
20 prepared
Unescaped Output
21
799 escaped
Nonce Checks
25
Capability Checks
3
File Operations
8
External Requests
6
Bundled Libraries
0

SQL Query Safety

83% prepared24 total queries

Output Escaping

97% escaped820 total outputs
Data Flows
All sanitized

Data Flow Analysis

6 flows
bws_add_menu_render (bws_menu\bws_menu.php:18)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Social Buttons Pack by BestWebSoft Attack Surface

Entry Points13
Unprotected0

AJAX Handlers 2

authwp_ajax_bws_submit_request_feature_actionbws_menu\class-bws-settings.php:1466
authwp_ajax_bws_submit_uninstall_reason_actionbws_menu\deactivation-form.php:433

Shortcodes 11

[bws_linkedin] bws-linkedin\bws-linkedin.php:401
[bws_pinterest_pin_it] bws-pinterest\bws-pinterest.php:640
[bws_pinterest_follow] bws-pinterest\bws-pinterest.php:642
[bws_pinterest_widget] bws-pinterest\bws-pinterest.php:644
[fb_button] facebook-button-plugin\facebook-button-plugin.php:915
[telegram_button] includes\sclbttns-mssngrs.php:456
[whatsapp_button] includes\sclbttns-mssngrs.php:457
[youtube_button] includes\sclbttns-mssngrs.php:458
[instagram_button] includes\sclbttns-nstgrm.php:186
[follow_me] twitter-plugin\twitter.php:398
[twitter_buttons] twitter-plugin\twitter.php:399
WordPress Hooks 67
actioninitbws-linkedin\bws-linkedin.php:392
actionadmin_initbws-linkedin\bws-linkedin.php:393
actionplugins_loadedbws-linkedin\bws-linkedin.php:394
actionadmin_enqueue_scriptsbws-linkedin\bws-linkedin.php:396
actionwp_enqueue_scriptsbws-linkedin\bws-linkedin.php:397
filterscript_loader_tagbws-linkedin\bws-linkedin.php:398
filterpgntn_callbackbws-linkedin\bws-linkedin.php:399
filterthe_contentbws-linkedin\bws-linkedin.php:402
filterbws_shortcode_button_contentbws-linkedin\bws-linkedin.php:404
filterbody_classbws-linkedin\bws-linkedin.php:406
actionplugins_loadedbws-pinterest\bws-pinterest.php:624
actioninitbws-pinterest\bws-pinterest.php:626
actionadmin_initbws-pinterest\bws-pinterest.php:627
actionwidgets_initbws-pinterest\bws-pinterest.php:629
actionadmin_enqueue_scriptsbws-pinterest\bws-pinterest.php:631
actionwp_enqueue_scriptsbws-pinterest\bws-pinterest.php:633
filterscript_loader_tagbws-pinterest\bws-pinterest.php:634
filterthe_contentbws-pinterest\bws-pinterest.php:636
filterpgntn_callbackbws-pinterest\bws-pinterest.php:637
filterbws_shortcode_button_contentbws-pinterest\bws-pinterest.php:646
filterload_textdomain_mofilebws_menu\bws_functions.php:43
filtermce_external_pluginsbws_menu\bws_functions.php:1294
filtermce_buttonsbws_menu\bws_functions.php:1295
actionadmin_initbws_menu\bws_functions.php:1581
actionadmin_enqueue_scriptsbws_menu\bws_functions.php:1582
actionadmin_headbws_menu\bws_functions.php:1583
actionadmin_footerbws_menu\bws_functions.php:1584
actionadmin_noticesbws_menu\bws_functions.php:1586
actionwp_enqueue_scriptsbws_menu\bws_functions.php:1588
filterthe_contentfacebook-button-plugin\facebook-button-plugin.php:121
filterthe_excerptfacebook-button-plugin\facebook-button-plugin.php:123
actionplugins_loadedfacebook-button-plugin\facebook-button-plugin.php:903
actioninitfacebook-button-plugin\facebook-button-plugin.php:904
actionadmin_initfacebook-button-plugin\facebook-button-plugin.php:905
actionloop_startfacebook-button-plugin\facebook-button-plugin.php:906
actionwp_enqueue_scriptsfacebook-button-plugin\facebook-button-plugin.php:908
actionadmin_enqueue_scriptsfacebook-button-plugin\facebook-button-plugin.php:909
actionwp_headfacebook-button-plugin\facebook-button-plugin.php:911
actionwp_footerfacebook-button-plugin\facebook-button-plugin.php:912
filterpgntn_callbackfacebook-button-plugin\facebook-button-plugin.php:913
filterbws_shortcode_button_contentfacebook-button-plugin\facebook-button-plugin.php:917
actionadmin_initincludes\sclbttns-mssngrs.php:454
filterthe_contentincludes\sclbttns-mssngrs.php:455
actionadmin_initincludes\sclbttns-nstgrm.php:182
filterthe_contentincludes\sclbttns-nstgrm.php:184
filterbws_shortcode_button_contentincludes\sclbttns-nstgrm.php:188
actionloop_startincludes\sclbttns-nstgrm.php:190
actionadmin_menusocial-buttons-pack.php:461
actionplugins_loadedsocial-buttons-pack.php:463
actioninitsocial-buttons-pack.php:464
actionadmin_initsocial-buttons-pack.php:465
actionadmin_enqueue_scriptssocial-buttons-pack.php:467
actionwp_enqueue_scriptssocial-buttons-pack.php:468
filterplugin_action_linkssocial-buttons-pack.php:470
filterplugin_row_metasocial-buttons-pack.php:471
actionadmin_noticessocial-buttons-pack.php:473
filterbody_classsocial-buttons-pack.php:475
actionplugins_loadedtwitter-plugin\twitter.php:388
actioninittwitter-plugin\twitter.php:389
actionadmin_inittwitter-plugin\twitter.php:391
actionwp_enqueue_scriptstwitter-plugin\twitter.php:393
actionwp_footertwitter-plugin\twitter.php:394
filterpgntn_callbacktwitter-plugin\twitter.php:395
actionadmin_enqueue_scriptstwitter-plugin\twitter.php:396
filterwidget_texttwitter-plugin\twitter.php:400
filterthe_contenttwitter-plugin\twitter.php:401
filterbws_shortcode_button_contenttwitter-plugin\twitter.php:403
Maintenance & Trust

Social Buttons Pack by BestWebSoft Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 10, 2025
PHP min version
Downloads40K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

Social Buttons Pack by BestWebSoft Developer Profile

bestweblayout

32 plugins · 17K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
1944 days
View full developer profile
Detection Fingerprints

How We Detect Social Buttons Pack by BestWebSoft

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-buttons-pack/css/admin_style.css/wp-content/plugins/social-buttons-pack/js/admin-script.js
Script Paths
/wp-content/plugins/social-buttons-pack/js/admin-script.js
Version Parameters
social-buttons-pack/css/admin_style.css?ver=social-buttons-pack/js/admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
sclbttns_settings_tabssclbttns_noticesclbttns_settings
Data Attributes
data-tabs-id='sclbttns_settings_tabs'
JS Globals
sclbttns_var
FAQ

Frequently Asked Questions about Social Buttons Pack by BestWebSoft