Social Share Button Security & Risk Analysis

wordpress.org/plugins/social-share-button

Awesome Share Button

1K active installs v2.1.14 PHP + WP 4.1+ Updated Jan 10, 2026
share-buttonsocial-sharesocial-share-buttonsocial-share-buttonssocial-share-plugin
100
A · Safe
CVEs total1
Unpatched0
Last CVENov 24, 2015
Safety Verdict

Is Social Share Button Safe to Use in 2026?

Generally Safe

Score 100/100

Social Share Button has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Nov 24, 2015Updated 4mo ago
Risk Assessment

The 'social-share-button' v2.1.14 plugin exhibits a generally good security posture, with a strong emphasis on using prepared statements for SQL queries and a very high rate of proper output escaping. The static analysis shows a limited attack surface, and importantly, no identified unsanitized paths in the taint analysis. The absence of dangerous functions and file operations further contributes to its secure design. However, the plugin has a history of vulnerabilities, specifically a past medium-severity Cross-Site Scripting (XSS) issue. While there are no currently unpatched CVEs, this historical pattern suggests a potential for introducing vulnerabilities, especially concerning input sanitization, which warrants continued vigilance. The presence of bundled libraries like Select2, while not explicitly flagged as outdated in this analysis, could be a vector for vulnerabilities if not kept updated by the plugin developer. The lack of capability checks on its entry points, although the number of entry points is small, is a minor concern that could be improved by implementing role-based access control.

Key Concerns

  • Medium severity XSS vulnerability in history
  • Bundled library (Select2) could be outdated
  • No capability checks on entry points
Vulnerabilities
1 published

Social Share Button Security Vulnerabilities

CVEs by Year

1 CVE in 2015
2015
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-0cfdb6de-41f8-4bea-a017-5708fceee762-social-share-buttonmedium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Social Share Button <= 2.1 - Stored Cross-Site Scripting

Nov 24, 2015 Patched in 2.1.1 (2982d)
Code Analysis
Analyzed Mar 16, 2026

Social Share Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
702 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

99% escaped708 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<settings> (includes\menu\settings.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Social Share Button Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_social_share_button_ajax_update_countincludes\functions.php:357
noprivwp_ajax_social_share_button_ajax_update_countincludes\functions.php:358

Shortcodes 1

[social_share_button] includes\class-shortcodes.php:8
WordPress Hooks 15
actionadmin_menuincludes\class-settings.php:12
actionssb_settings_tabs_content_optionsincludes\functions-settings.php:6
actionssb_settings_tabs_content_styleincludes\functions-settings.php:226
actionssb_settings_tabs_content_displayincludes\functions-settings.php:329
actionssb_settings_tabs_content_shortcodeincludes\functions-settings.php:579
actionssb_settings_tabs_content_custom_scriptsincludes\functions-settings.php:691
actionssb_settings_tabs_content_help_supportincludes\functions-settings.php:741
filtersocial_share_button_filter_buttons_beforeincludes\functions.php:96
actionwp_headincludes\functions.php:133
actionthe_contentincludes\functions.php:142
actionthe_excerptincludes\functions.php:254
actionwp_footerincludes\functions.php:383
actionwp_enqueue_scriptssocial-share-button.php:48
actionadmin_enqueue_scriptssocial-share-button.php:49
actionplugins_loadedsocial-share-button.php:52
Maintenance & Trust

Social Share Button Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 10, 2026
PHP min version
Downloads126K

Community Trust

Rating82/100
Number of ratings17
Active installs1K
Developer Profile

Social Share Button Developer Profile

PickPlugins

14 plugins · 94K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
330 days
View full developer profile
Detection Fingerprints

How We Detect Social Share Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-share-button/assets/front/js/scripts.js/wp-content/plugins/social-share-button/assets/front/css/style.css/wp-content/plugins/social-share-button/assets/global/css/fontawesome-5.min.css/wp-content/plugins/social-share-button/assets/admin/js/select2.full.js/wp-content/plugins/social-share-button/assets/admin/css/select2.min.css/wp-content/plugins/social-share-button/assets/admin/js/jquery.lazy.min.js/wp-content/plugins/social-share-button/assets/settings-tabs/settings-tabs.css/wp-content/plugins/social-share-button/assets/settings-tabs/settings-tabs.js
Script Paths
/wp-content/plugins/social-share-button/assets/front/js/scripts.js/wp-content/plugins/social-share-button/assets/admin/js/select2.full.js/wp-content/plugins/social-share-button/assets/admin/js/jquery.lazy.min.js/wp-content/plugins/social-share-button/assets/settings-tabs/settings-tabs.js
Version Parameters
social-share-button/assets/front/js/scripts.js?ver=1.0.0social-share-button/assets/front/css/style.css?ver=1.0.0social-share-button/assets/global/css/fontawesome-5.min.css?ver=5.0.0social-share-button/assets/admin/js/select2.full.js?ver=4.0.0social-share-button/assets/admin/css/select2.min.css?ver=4.0.0social-share-button/assets/admin/js/jquery.lazy.min.js?ver=1.0.0social-share-button/assets/settings-tabs/settings-tabs.css?ver=1.0.0social-share-button/assets/settings-tabs/settings-tabs.js?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
social-share-button-containersocial-share-buttons
Data Attributes
data-social-share-button-id
JS Globals
social_share_button_ajax
FAQ

Frequently Asked Questions about Social Share Button