
Tce Sharing Security & Risk Analysis
wordpress.org/plugins/tce-sharingPublish content on https://tce.exchange
Is Tce Sharing Safe to Use in 2026?
Generally Safe
Score 85/100Tce Sharing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The tce-sharing v2.0.9 plugin exhibits a mixed security posture. On one hand, the plugin demonstrates good practices by exclusively using prepared statements for its SQL queries and has no recorded vulnerability history (CVEs). The absence of detected taint flows with unsanitized paths is also a positive indicator. However, several significant concerns emerge from the static code analysis. The presence of 22 'dangerous functions' such as `shell_exec`, `assert`, `unserialize`, and `passthru` is a major red flag, as these functions can be exploited for remote code execution or deserialization vulnerabilities if not handled with extreme care and robust sanitization, which appears to be lacking given the low capability check count and zero nonce checks. Furthermore, the output escaping is only 56% proper, suggesting a risk of cross-site scripting (XSS) vulnerabilities in the plugin's output. The presence of bundled libraries, specifically Guzzle, without information on their version or patching status, introduces a potential risk of leveraging known vulnerabilities in that library.
Key Concerns
- Dangerous functions used (shell_exec, assert, etc.)
- Low percentage of properly escaped output
- No nonce checks on potential entry points
- Bundled library (Guzzle) without version info
- Limited capability checks
Tce Sharing Security Vulnerabilities
Tce Sharing Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Tce Sharing Attack Surface
Maintenance & Trust
Tce Sharing Maintenance & Trust
Maintenance Signals
Community Trust
Tce Sharing Alternatives
Broadcast
threewp-broadcast
Network content syndication made easy! Automatically share content by multiposting between multisite blogs.
Syndication Links
syndication-links
Link to copies of your cross-posted content in other social networks or websites.
The Publisher Desk – Headlines Plus Widget
headlines-plus-widget
Headlines Plus: Free plugin for WordPress to grow your audience with traffic sharing, syndication, and lazy-loading widgets or shortcodes.
Revive To Sky – Post old content to Bluesky
revive-to-sky
Automatically syndicate your old blog posts to Bluesky on a regular basis, increasing traffic and engagement automatically.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Tce Sharing Developer Profile
1 plugin · 10 total installs
How We Detect Tce Sharing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tce-sharing/dist/css/main.css/wp-content/plugins/tce-sharing/dist/js/bundle.js/wp-content/plugins/tce-sharing/dist/js/tce-sharing-app.js/wp-content/plugins/tce-sharing/dist/js/bundle.js/wp-content/plugins/tce-sharing/dist/js/tce-sharing-app.jstce-sharing/dist/css/main.css?ver=tce-sharing/dist/js/bundle.js?ver=tce-sharing/dist/js/tce-sharing-app.js?ver=HTML / DOM Fingerprints
TCE_SHARING_API_ENDPOINTTCE_SHARING_AWS_REGIONTCE_SHARING_AWS_USER_POOLTCE_SHARING_AWS_USER_POOL_WEBCLIENTTCE_SHARING_AWS_IDENTITY_POOL/wp-json/tce-sharing/v1/