Superb Social Media Share Buttons and Follow Buttons Security & Risk Analysis

wordpress.org/plugins/superb-social-share-and-follow-buttons

Social Media Share Buttons & Follow Buttons. Social Share Icons. 25+ Social networks. Icon & Button Shortcodes. Floating Sidebar.

7K active installs v1.2.5 PHP 5.6+ WP 4.9+ Updated Jan 21, 2026
buttonsfollowmediasharesocial
99
A · Safe
CVEs total2
Unpatched0
Last CVEApr 6, 2023
Download
Safety Verdict

Is Superb Social Media Share Buttons and Follow Buttons Safe to Use in 2026?

Generally Safe

Score 99/100

Superb Social Media Share Buttons and Follow Buttons has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Apr 6, 2023Updated 2mo ago
Risk Assessment

The "superb-social-share-and-follow-buttons" plugin v1.2.5 exhibits a mixed security posture. On the positive side, the static analysis shows a strong adherence to secure coding practices regarding SQL queries, utilizing prepared statements exclusively. Furthermore, there are no detected critical or high-severity taint flows, and file operations and external HTTP requests are absent, which significantly reduces certain attack vectors. The presence of nonce and capability checks on entry points is also commendable.

However, a significant concern arises from the plugin's vulnerability history. It has two known medium-severity CVEs, both of which are reported as patched. While this is good, the common vulnerability types associated with these CVEs – Missing Authorization and Cross-Site Request Forgery (CSRF) – suggest a recurring pattern in how the plugin handles user input and access control. The static analysis indicates a small number of entry points, but the absence of explicit checks for all AJAX handlers could potentially be exploited if authorization is not implicitly handled elsewhere. The moderate percentage of properly escaped output (72%) also presents a potential risk for cross-site scripting (XSS) vulnerabilities.

In conclusion, while the plugin demonstrates good practices in areas like SQL querying and avoiding dangerous functions, the historical prevalence of authorization and CSRF vulnerabilities, coupled with the minor concern of imperfect output escaping, warrants careful consideration. Users should ensure they are running the latest patched version and remain vigilant for any future security advisories.

Key Concerns

  • Medium severity CVEs in history
  • Output escaping is not fully proper (72%)
  • Vulnerability types include Missing Authorization
  • Vulnerability types include CSRF
Vulnerabilities
2

Superb Social Media Share Buttons and Follow Buttons Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2023-29428medium · 4.3Missing Authorization

Superb Social Media Share Buttons and Follow Buttons <= 1.1.3 - Missing Authorization via spbsmAjax

Apr 6, 2023 Patched in 1.1.5 (292d)

Superb Social Media Share Buttons and Follow Buttons <= 1.1.3 - Cross-Site Request Forgery via spbsmAjax

Apr 6, 2023 Patched in 1.1.5 (292d)
Code Analysis
Analyzed Mar 16, 2026

Superb Social Media Share Buttons and Follow Buttons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
14 prepared
Unescaped Output
45
116 escaped
Nonce Checks
6
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared14 total queries

Output Escaping

72% escaped161 total outputs
Attack Surface

Superb Social Media Share Buttons and Follow Buttons Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 2

authwp_ajax_spbsmAjaxplugin.php:51
authwp_ajax_spbrec_dismiss_noticerecommender\recommender.php:77

Shortcodes 2

[spbsm-share-buttons] plugin.php:52
[spbsm-follow-buttons] plugin.php:53
WordPress Hooks 10
actioninitinc\data\db.php:35
actioninitplugin.php:46
actionadmin_menuplugin.php:47
actionadmin_enqueue_scriptsplugin.php:48
actionwp_enqueue_scriptsplugin.php:49
filterplugin_row_metaplugin.php:50
filterthe_contentplugin.php:290
filterwp_footerplugin.php:291
actionadmin_noticesrecommender\recommender.php:76
actionadmin_initrecommender\recommender.php:78
Maintenance & Trust

Superb Social Media Share Buttons and Follow Buttons Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 21, 2026
PHP min version5.6
Downloads215K

Community Trust

Rating88/100
Number of ratings11
Active installs7K
Developer Profile

Superb Social Media Share Buttons and Follow Buttons Developer Profile

Suplugins

6 plugins · 108K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
197 days
View full developer profile
Detection Fingerprints

How We Detect Superb Social Media Share Buttons and Follow Buttons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/superb-social-share-and-follow-buttons/assets/css/backend.css/wp-content/plugins/superb-social-share-and-follow-buttons/assets/css/frontend.css/wp-content/plugins/superb-social-share-and-follow-buttons/assets/lato/styles.css/wp-content/plugins/superb-social-share-and-follow-buttons/js/jquery.tablednd.js/wp-content/plugins/superb-social-share-and-follow-buttons/js/backend.js
Script Paths
/wp-content/plugins/superb-social-share-and-follow-buttons/js/jquery.tablednd.js/wp-content/plugins/superb-social-share-and-follow-buttons/js/backend.js
Version Parameters
superb-social-share-and-follow-buttons/assets/css/backend.css?ver=superb-social-share-and-follow-buttons/assets/css/frontend.css?ver=superb-social-share-and-follow-buttons/assets/lato/styles.css?ver=superb-social-share-and-follow-buttons/js/jquery.tablednd.js?ver=superb-social-share-and-follow-buttons/js/backend.js?ver=

HTML / DOM Fingerprints

CSS Classes
spbsm-backendspbsm-stylesheetspbsm-lato-font
HTML Comments
<!-- Superb Social Share and Follow Buttons -->
JS Globals
msgs
Shortcode Output
[spbsm-share-buttons][spbsm-follow-buttons]
FAQ

Frequently Asked Questions about Superb Social Media Share Buttons and Follow Buttons