Social Share Buttons Security & Risk Analysis
wordpress.org/plugins/social-share-floating-iconsSocial Share is fully loaded with social media options, allows you to add Social buttons on your WordPress site to share your content on the web with …
Is Social Share Buttons Safe to Use in 2026?
Generally Safe
Score 85/100Social Share Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "social-share-floating-icons" v3.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of known vulnerabilities in its history, coupled with no reported critical or high-severity issues, is a positive indicator. The code analysis reveals a clean slate regarding dangerous functions, SQL injection risks (all queries use prepared statements), file operations, and external HTTP requests. This suggests a developer who is mindful of common web application vulnerabilities.
However, there are significant areas of concern primarily stemming from the code analysis. The most notable issue is the low percentage of properly escaped output (22%), which, despite the absence of explicit taint flows or dangerous functions in this analysis, represents a substantial risk. This indicates that user-supplied data, if it reaches these unescaped outputs, could be exploited for Cross-Site Scripting (XSS) attacks. Furthermore, the complete lack of nonce and capability checks across all potential entry points (though the entry points are currently zero) suggests a potential oversight in security implementation that could become a vulnerability if new entry points are introduced or if the analysis did not cover all potential interaction vectors.
In conclusion, while the plugin's history is spotless and many secure coding practices are evident, the low output escaping percentage and the absence of common security checks on entry points are critical weaknesses. These factors introduce a real risk of XSS vulnerabilities. A thorough security audit focusing on output sanitization and exploring all potential interaction points would be highly recommended to confirm the plugin's security.
Key Concerns
- Low output escaping percentage (22%)
- No nonce checks on potential entry points
- No capability checks on potential entry points
Social Share Buttons Security Vulnerabilities
Social Share Buttons Code Analysis
Output Escaping
Social Share Buttons Attack Surface
WordPress Hooks 8
Maintenance & Trust
Social Share Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Social Share Buttons Alternatives
Social Media Social Share Icon
add-social-share
Social Media Share Icons to increase social traffic and popularity. Social sharing to Facebook , Twitter, Pinterest,LinkedIn and Google Plus social me …
Simpliest Social Share
cvw-social-share
Share your posts and Woocommerce products in social media, Whatsapp, Telegram and Email without losing web performance.
Jamie Social Icons
jamie-social-icons
Share your posts & pages with your favourite social sites - Twitter, Facebook, Google Plus, Pinterest And LinkedIn and now trackable with your Goo …
AK Sharing Buttons
ak-sharing-buttons
Ajax load and append a list of sharing button to single-post, static-page. Ex: facebook, twitter, pinterst, google-plus, linkedin.
CSS Share Buttons
css-share-buttons
Facebook, Twitter, Google Plus and LinkedIn Share buttons. Super Fast Loading, No Javascript, Only CSS. Responsive Design, Floting Sidebar Option
Social Share Buttons Developer Profile
5 plugins · 550 total installs
How We Detect Social Share Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-share-floating-icons/css/style.css/wp-content/plugins/social-share-floating-icons/css/hover.css/wp-content/plugins/social-share-floating-icons/js/theme-selection.js/wp-content/plugins/social-share-floating-icons/js/theme-selection.jssocial-share-floating-icons/css/style.css?ver=social-share-floating-icons/css/hover.css?ver=social-share-floating-icons/js/theme-selection.js?ver=HTML / DOM Fingerprints
wpssfi-post-divwpsfb-floating-icon-themeid="wpsfb-floating-icon-theme"id="wpsfb-user-selected-facebook"id="wpsfb-user-selected-twitter"id="wpsfb-user-selected-google"id="wpsfb-user-selected-pinterest"id="wpsfb-user-selected-linkedin"+11 morewpsfb_load_custom_wp_admin_stylewpafi_plugin_create_menuwpafi_register_plugin_settingswpsfb_sanitize_optionswpssfi_delete_optionswpssfi_add_icons_home_post+1 more