Social Media Feather | social media sharing Security & Risk Analysis

wordpress.org/plugins/social-media-feather

Lightweight, modern looking and effective social media sharing and profile buttons and icons. All your social media needs in 1 easy package!

20K active installs v2.2.1 PHP + WP 5.9+ Updated Nov 11, 2025
facebooksharesocial-buttonssocial-mediasocial-sharing
99
A · Safe
CVEs total2
Unpatched0
Last CVEDec 7, 2023
Safety Verdict

Is Social Media Feather | social media sharing Safe to Use in 2026?

Generally Safe

Score 99/100

Social Media Feather | social media sharing has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Dec 7, 2023Updated 4mo ago
Risk Assessment

The social-media-feather v2.2.1 plugin demonstrates a generally good security posture based on the static analysis. It exhibits a low attack surface with all identified entry points (AJAX handlers, REST API routes, and shortcodes) having appropriate authorization and permission checks. The plugin also performs well in code signals, with no dangerous functions or file operations, all SQL queries using prepared statements, and a high percentage of properly escaped output. Furthermore, the presence of nonce and capability checks is encouraging.

However, the vulnerability history presents a significant concern. The plugin has a history of two known medium-severity CVEs, one of which was reported relatively recently (December 2023). The common vulnerability types reported (Missing Authorization and Cross-site Scripting) indicate recurring issues that require diligent patching. While there are no currently unpatched vulnerabilities reported, this history suggests potential blind spots in the development process or a tendency for certain types of vulnerabilities to re-emerge.

In conclusion, while the static analysis reveals a codebase that generally adheres to secure coding practices, the historical vulnerability data warrants caution. The plugin's strengths lie in its controlled attack surface and robust code sanitization. The weakness is primarily rooted in its past security incidents, suggesting that users should remain vigilant and ensure the plugin is always updated to the latest available version, even if no critical or high vulnerabilities are currently known.

Key Concerns

  • Known medium-severity CVEs in history
  • Past XSS and Missing Auth vulnerabilities
Vulnerabilities
2

Social Media Feather | social media sharing Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2023-49861medium · 4.3Missing Authorization

Social Media Feather <= 2.1.3 - Missing Authorization

Dec 7, 2023 Patched in 2.1.4 (47d)
CVE-2021-36848medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Social Media Feather <= 2.0.4 - Authenticated (Admin+) Stored Cross-Site Scripting

Feb 10, 2022 Patched in 2.0.5 (711d)
Code Analysis
Analyzed Mar 16, 2026

Social Media Feather | social media sharing Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
112 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped118 total outputs
Attack Surface

Social Media Feather | social media sharing Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 2

authwp_ajax_smf_ajax_hide_reviewsynved-connect\synved-connect.php:145
authwp_ajax_feather_hide_termssynved-social\synved-social-setup.php:1083

REST API Routes 1

POST/wp-json/social-media-feather/v2/settingsphp\class-socialmediafeather.php:131

Shortcodes 4

[feather_share] synved-social\synved-social-setup.php:1050
[synved_feather_share] synved-social\synved-social-setup.php:1051
[feather_follow] synved-social\synved-social-setup.php:1052
[synved_feather_follow] synved-social\synved-social-setup.php:1053
WordPress Hooks 18
filterscript_loader_tagphp\class-socialmediafeather.php:925
actioninitsynved-connect\synved-connect.php:143
actionadmin_enqueue_scriptssynved-connect\synved-connect.php:144
actionwp_headsynved-option\synved-option.php:694
actionafter_setup_themesynved-option\synved-option.php:1038
actioninitsynved-option\synved-option.php:1039
filterupgrader_source_selectionsynved-option\synved-option.php:1040
filterupgrader_pre_installsynved-option\synved-option.php:1041
filterupgrader_post_installsynved-option\synved-option.php:1042
filtersafe_style_csssynved-option\synved-option.php:1045
actionadmin_initsynved-option\synved-option.php:1056
actionadmin_enqueue_scriptssynved-option\synved-option.php:1057
filterwidget_textsynved-social\synved-social-setup.php:942
filterthe_contentsynved-social\synved-social-setup.php:1060
actionadmin_noticessynved-social\synved-social-setup.php:1082
actioninitsynved-social\synved-social-setup.php:1088
actionwidgets_initsynved-social\synved-social-setup.php:1090
actionadmin_enqueue_scriptssynved-social\synved-social-setup.php:1093
Maintenance & Trust

Social Media Feather | social media sharing Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 11, 2025
PHP min version
Downloads2.0M

Community Trust

Rating92/100
Number of ratings506
Active installs20K
Developer Profile

Social Media Feather | social media sharing Developer Profile

socialmediafeather

1 plugin · 20K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
379 days
View full developer profile
Detection Fingerprints

How We Detect Social Media Feather | social media sharing

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-media-feather/build/loader.js/wp-content/plugins/social-media-feather/build/index.js/wp-content/plugins/social-media-feather/build/index.css
Script Paths
/wp-content/plugins/social-media-feather/build/loader.js/wp-content/plugins/social-media-feather/build/index.js
Version Parameters
social-media-feather/build/loader.js?ver=social-media-feather/build/index.js?ver=social-media-feather/build/index.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-synved-social-provider
JS Globals
SocialMediaFeather
REST Endpoints
/wp-json/social-media-feather/v2/settings
Shortcode Output
<div id="social-media-feather-app"></div>
FAQ

Frequently Asked Questions about Social Media Feather | social media sharing