The J A Mortram Share This Story Security & Risk Analysis

wordpress.org/plugins/the-j-a-mortram-share-this-story

Adds 'Share This Story' buttons to the end of a single post before the comments. Posts can be shared on Twitter, Facebook and Google+.

10 active installs v1.12 PHP + WP 3.0+ Updated Nov 15, 2017
sharingsocial-mediathe-j-a-mortram
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is The J A Mortram Share This Story Safe to Use in 2026?

Generally Safe

Score 85/100

The J A Mortram Share This Story has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin 'the-j-a-mortram-share-this-story' v1.12 exhibits a mixed security posture. On the positive side, static analysis reveals no reported vulnerabilities in its history, no dangerous functions, and all SQL queries utilize prepared statements, which are strong indicators of good development practices. The absence of external HTTP requests and file operations also reduces potential attack vectors. However, a significant concern arises from the complete lack of output escaping for all eight identified output points. This means that any user-supplied data rendered directly to the page could potentially lead to cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user's browser. Furthermore, the absence of nonce checks and capability checks across all entry points, coupled with zero AJAX handlers and REST API routes (which typically would have these), suggests a potential oversight in securing actions and data access, although the limited attack surface mitigates immediate exploitation in this specific version. The lack of taint analysis data is not a direct security flaw but rather an inability to fully assess data flow risks within the plugin.

Key Concerns

  • All outputs are unescaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

The J A Mortram Share This Story Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

The J A Mortram Share This Story Release Timeline

v1.11
v1.10
v1.09
v1.08
v1.07
v1.06
v1.05
v1.04
v1.03
Code Analysis
Analyzed Mar 17, 2026

The J A Mortram Share This Story Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

The J A Mortram Share This Story Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptsjamortram-share.php:28
filtercomments_templatejamortram-share.php:29
Maintenance & Trust

The J A Mortram Share This Story Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 15, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

The J A Mortram Share This Story Developer Profile

bigflannel

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect The J A Mortram Share This Story

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/the-j-a-mortram-share-this-story/jamortram-share.css/wp-content/plugins/the-j-a-mortram-share-this-story/img/twitter.png/wp-content/plugins/the-j-a-mortram-share-this-story/img/facebook.png/wp-content/plugins/the-j-a-mortram-share-this-story/img/gplus.png
Version Parameters
the-j-a-mortram-share-this-story/jamortram-share.css?ver=

HTML / DOM Fingerprints

CSS Classes
jam-centerjam-social-share
FAQ

Frequently Asked Questions about The J A Mortram Share This Story