Social Share Watermark Security & Risk Analysis

wordpress.org/plugins/social-share-watermark

Social Share Watermark.

300 active installs v2.1.0 PHP + WP 3.0+ Updated Nov 9, 2022
socialsocial-sharewatermark
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Share Watermark Safe to Use in 2026?

Generally Safe

Score 85/100

Social Share Watermark has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "social-share-watermark" plugin v2.1.0 demonstrates a strong adherence to several WordPress security best practices. Static analysis reveals no dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. Furthermore, there are no file operations or external HTTP requests that are immediately flagged as concerning, and the plugin has no recorded vulnerability history, suggesting a history of responsible development. The absence of reported CVEs is a positive indicator of its past security.

However, the complete lack of nonce checks and capability checks across all entry points is a significant concern. While the current attack surface appears to be zero, this indicates a potential vulnerability if new features or entry points are added without proper authorization mechanisms. The presence of two external HTTP requests also warrants careful scrutiny, as these could be vectors for vulnerabilities if not handled securely and if the remote endpoints are compromised or maliciously crafted.

In conclusion, the plugin exhibits good fundamental coding practices regarding data handling and output. The primary weakness lies in the complete absence of authorization checks, which, while not currently exploited due to a minimal attack surface, leaves the plugin vulnerable to potential privilege escalation or unauthorized actions should its entry points expand or be manipulated. The external HTTP requests, while only two, represent a minor, but present, area of potential risk.

Key Concerns

  • Complete absence of nonce checks
  • Complete absence of capability checks
  • Presence of external HTTP requests
Vulnerabilities
None known

Social Share Watermark Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Social Share Watermark Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
20 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped20 total outputs
Attack Surface

Social Share Watermark Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_menuincludes\admin-menu.php:26
actionadmin_initincludes\admin-menu.php:27
actionadmin_enqueue_scriptssocial-media-Share-Watermark.php:25
filterplugin_row_metasocial-media-Share-Watermark.php:29
filterquery_varssocial-media-Share-Watermark.php:48
actiontemplate_redirectsocial-media-Share-Watermark.php:51
filterwpseo_opengraph_imagesocial-media-Share-Watermark.php:102
filterrank_math/opengraph/facebook/imagesocial-media-Share-Watermark.php:103
actionwp_headsocial-media-Share-Watermark.php:104
filteraioseo_facebook_tagssocial-media-Share-Watermark.php:105
actionsave_postsocial-media-Share-Watermark.php:125
actionwp_headsocial-media-Share-Watermark.php:143
Maintenance & Trust

Social Share Watermark Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.0
Last updatedNov 9, 2022
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings5
Active installs300
Developer Profile

Social Share Watermark Developer Profile

Rasedul Haque Rumi

8 plugins · 3K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Social Share Watermark

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-share-watermark/social-media-uploader.js
Script Paths
social-media-uploader.js
Version Parameters
social-media-uploader.js?ver=1.0.0

HTML / DOM Fingerprints

HTML Comments
<!-- This is free Plugin Don Not edit Or remove Main Developers Name -->
FAQ

Frequently Asked Questions about Social Share Watermark