
Social Linkz – Lightweight and fast social media sharing plugin Security & Risk Analysis
wordpress.org/plugins/social-linkzSocial Linkz plugin helps you easily share your content to social media.
Is Social Linkz – Lightweight and fast social media sharing plugin Safe to Use in 2026?
Generally Safe
Score 100/100Social Linkz – Lightweight and fast social media sharing plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The social-linkz plugin v1.8.9 exhibits a generally good security posture based on the provided static analysis. There are no identified critical or high severity vulnerabilities from taint analysis, and the plugin has no recorded vulnerability history, indicating a stable and potentially well-maintained codebase. The use of prepared statements for all SQL queries and the presence of nonce and capability checks are positive security practices. However, there are areas for concern that warrant attention. Notably, 49% of output operations are not properly escaped, presenting a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being displayed. Furthermore, two flows with unsanitized paths were identified, which could potentially lead to path traversal or other file-related vulnerabilities, although the absence of file operations in the static analysis mitigates this risk in the current version.
While the plugin boasts a zero attack surface in terms of AJAX, REST API, shortcodes, and cron events, this analysis might not be exhaustive. The bundling of the Freemius library at version 1.0 is a potential concern if it's an older version and contains known vulnerabilities, though no specific information on its version's security status is provided. The balanced conclusion is that while the plugin avoids common pitfalls like raw SQL and a broad attack surface, the unescaped output and unsanitized path flows represent tangible risks that should be addressed to further strengthen its security.
Key Concerns
- Insufficient output escaping detected
- Unsanitized paths found in taint analysis
- Bundled library potentially outdated (Freemius v1.0)
Social Linkz – Lightweight and fast social media sharing plugin Security Vulnerabilities
Social Linkz – Lightweight and fast social media sharing plugin Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Social Linkz – Lightweight and fast social media sharing plugin Attack Surface
WordPress Hooks 27
Maintenance & Trust
Social Linkz – Lightweight and fast social media sharing plugin Maintenance & Trust
Maintenance Signals
Community Trust
Social Linkz – Lightweight and fast social media sharing plugin Alternatives
Simple Social Media Share Buttons – Social Sharing for Everyone
simple-social-buttons
This Social Share Plugin adds advanced social media sharing buttons to your WordPress sites, such as Facebook, WhatsApp, X, LinkedIn, & Pinterest.
WP Socializer – Simple & Easy Social Media Share Icons
wp-socializer
Simple & easy plugin to add social media sharing icons, buttons like Facebook, Twitter, WhatsApp, Instagram & more
WPUpper Share Buttons
wpupper-share-buttons
Free social share buttons, share to Facebook, WhatsApp, Messenger, Twitter, Reddit and much more.
Super Simple Social Share Icons
super-simple-social-share-icons
A lightweight and powerful solution for adding beautiful social sharing buttons to your WordPress site.
Fastest Share Buttons
fastest-share-buttons
Fastest Share Buttons for WordPress - An extremely fast and mobile friendly social share plugin - no JS, no external API, with SVG icons, cache compat …
Social Linkz – Lightweight and fast social media sharing plugin Developer Profile
14 plugins · 31K total installs
How We Detect Social Linkz – Lightweight and fast social media sharing plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-linkz/lite/dist/styles/app.css/wp-content/plugins/social-linkz/lite/dist/styles/social-linkz-admin.css/wp-content/plugins/social-linkz/lite/dist/styles/social-linkz.css/wp-content/plugins/social-linkz/lite/dist/scripts/app.js/wp-content/plugins/social-linkz/lite/dist/scripts/social-linkz.js/wp-content/plugins/social-linkz/lite/dist/scripts/social-linkz-admin.js/wp-content/plugins/social-linkz/lite/dist/scripts/app.js/wp-content/plugins/social-linkz/lite/dist/scripts/social-linkz.js/wp-content/plugins/social-linkz/lite/dist/scripts/social-linkz-admin.jssocial-linkz/lite/dist/styles/app.css?ver=social-linkz/lite/dist/styles/social-linkz-admin.css?ver=social-linkz/lite/dist/styles/social-linkz.css?ver=social-linkz/lite/dist/scripts/app.js?ver=social-linkz/lite/dist/scripts/social-linkz.js?ver=social-linkz/lite/dist/scripts/social-linkz-admin.js?ver=HTML / DOM Fingerprints
social-linkz-main-wrapsocial-linkz-wrapsocial-linkz-containersocial-linkz-itemsocial-linkz-labelsocial-linkz-iconsocial-linkz-sharesocial-linkz-social-iconThis function is provided for demonstration purposes only.An instance of this class should be passed to the run() functiondefined in Social Linkz_Loader as all of the hooks are definedin that particular class.+3 moredata-social-linkz-iddata-social-linkz-typeSocialLinkzAppsocial_linkz_admin_object