
Social Media Share Buttons and Link Shortener 4eq Security & Risk Analysis
wordpress.org/plugins/social-media-share-buttons-and-link-shortener-4eqHere is a short description of the plugin. This should be no more than 150 characters. No markup here.
Is Social Media Share Buttons and Link Shortener 4eq Safe to Use in 2026?
Generally Safe
Score 85/100Social Media Share Buttons and Link Shortener 4eq has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "social-media-share-buttons-and-link-shortener-4eq" v1.0* exhibits a mixed security posture. On the positive side, it has a very small attack surface with only one identified entry point (a shortcode), and critically, no AJAX handlers or REST API routes were found to be unprotected. The code also demonstrates good practices by exclusively using prepared statements for its SQL queries and not performing any file operations or external HTTP requests from potentially untrusted input. The absence of known vulnerabilities in its history is also a positive indicator.
However, significant concerns arise from the lack of output escaping. With 100% of its outputs not being properly escaped, this plugin presents a considerable risk of Cross-Site Scripting (XSS) vulnerabilities. Any data rendered by the plugin without proper sanitization or escaping could be exploited by attackers to inject malicious scripts. Furthermore, the complete absence of nonce checks and capability checks on its entry points means that even the single shortcode could potentially be triggered by unauthenticated or unauthorized users, depending on its implementation. The lack of taint analysis data also means that potential issues related to unsanitized data flows remain unverified.
In conclusion, while the plugin benefits from a limited attack surface and secure SQL handling, the critical failure in output escaping and the absence of essential security checks (nonces and capabilities) on its sole entry point are significant weaknesses. The lack of a vulnerability history is good, but it doesn't negate the present risks identified in the static analysis. Developers should prioritize addressing the output escaping and implementing proper authorization checks.
Key Concerns
- Unescaped output found
- Missing nonce checks
- Missing capability checks
Social Media Share Buttons and Link Shortener 4eq Security Vulnerabilities
Social Media Share Buttons and Link Shortener 4eq Code Analysis
Output Escaping
Social Media Share Buttons and Link Shortener 4eq Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Social Media Share Buttons and Link Shortener 4eq Maintenance & Trust
Maintenance Signals
Community Trust
Social Media Share Buttons and Link Shortener 4eq Alternatives
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds
facebook-pagelike-widget
Floating Social Media Icons, Sticky Share Buttons, Facebook Feeds, & Popup builder. Also, create Call, Email, SMS, & Contact buttons to increa …
Simple Social Media Share Buttons – Social Sharing for Everyone
simple-social-buttons
This Social Share Plugin adds advanced social media sharing buttons to your WordPress sites, such as Facebook, WhatsApp, X, LinkedIn, & Pinterest.
Social Media Share Buttons and Link Shortener 4eq Developer Profile
3 plugins · 40 total installs
How We Detect Social Media Share Buttons and Link Shortener 4eq
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-media-share-buttons-and-link-shortener-4eq/css1.css/wp-content/plugins/social-media-share-buttons-and-link-shortener-4eq/css1.jsHTML / DOM Fingerprints
smsbals4<!-- Add font awesome icons -->onclick="myFunction_smsbals4()"myFunction_smsbals4<div id="shareiconsaeedolesh"><a href="#" class="fa fa-share-alt smsbals4"<div id="shareiconsaeed" style="display:none;"><a href="https://www.facebook.com/sharer.php?u=