Social Media Share Buttons & Social Sharing Icons Security & Risk Analysis
wordpress.org/plugins/ultimate-social-media-iconsShare buttons and pop up share icons for social media sharing
Is Social Media Share Buttons & Social Sharing Icons Safe to Use in 2026?
Generally Safe
Score 96/100Social Media Share Buttons & Social Sharing Icons has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "ultimate-social-media-icons" plugin exhibits a mixed security posture. While it demonstrates good practices such as 100% use of prepared statements for SQL queries and a significant proportion of properly escaped outputs, several concerning areas warrant attention. The presence of two unprotected AJAX handlers significantly increases the attack surface, potentially allowing unauthorized actions without proper authentication. Furthermore, the use of the `unserialize` function is a known security risk, especially if the data being unserialized originates from untrusted user input. The plugin's vulnerability history is a major red flag, with 11 known CVEs, including a significant number of medium severity and one high severity issue in the past. While there are currently no unpatched vulnerabilities, the pattern of past issues, particularly Cross-Site Scripting, CSRF, and Missing Authorization, suggests a recurring tendency for security weaknesses. This indicates a need for more rigorous security testing and code review during development to prevent future vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- Use of unserialize function
- High number of past CVEs
- Past high severity CVEs
- Flows with unsanitized paths
- Output escaping not fully implemented
Social Media Share Buttons & Social Sharing Icons Security Vulnerabilities
CVEs by Year
Severity Breakdown
11 total CVEs
Social Media Share Buttons & Social Sharing Icons <= 2.9.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Social Media & Share Icons <= 2.9.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Social Media Share Buttons <= 2.8.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
Social Media Share Buttons & Social Sharing Icons <= 2.8.5 - Cross-Site Request Forgery
Social Media Share Buttons & Social Sharing Icons <= 2.8.5 - Information Exposure
Social Media & Share Icons <= 2.8.3 - Reflected Cross-Site Scripting
Social Media & Share Icons <= 2.8.1 - Missing Authorization via handle_installation
Social Media Share Buttons & Social Sharing Icons <= 2.1.7 - Reflected Cross-Site Scripting
Social Media Share Buttons & Social Sharing Icons <= 1.5.1 - Arbitrary Options Deletion
Social Media Share Buttons & Social Sharing Icons <= 1.2.1 - Unspecified Vulnerabilities
Social Media Share Buttons & Social Sharing Icons < 1.1.1.12 - Authenticated Stored Cross-Site Scripting
Social Media Share Buttons & Social Sharing Icons Release Timeline
Social Media Share Buttons & Social Sharing Icons Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Social Media Share Buttons & Social Sharing Icons Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 27
Scheduled Events 1
Maintenance & Trust
Social Media Share Buttons & Social Sharing Icons Maintenance & Trust
Maintenance Signals
Community Trust
Social Media Share Buttons & Social Sharing Icons Alternatives
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
WPUpper Share Buttons
wpupper-share-buttons
Free social share buttons, share to Facebook, WhatsApp, Messenger, Twitter, Reddit and much more.
Easy Share Solution For WordPress
easy-share-solution
A powerful, easy-to-use WordPress social sharing plugin with modern share buttons, built-in analytics, and smooth dashboard integration.
Advanced Social icons
advance-social-icons
Advanced social icons help you quickly add icons with links to your profile on different social media platforms.
Social Media Share Buttons & Social Sharing Icons Developer Profile
6 plugins · 610K total installs
How We Detect Social Media Share Buttons & Social Sharing Icons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ultimate-social-media-icons/css/sfsi-landing-page.css/wp-content/plugins/ultimate-social-media-icons/css/sfsi-mobile.css/wp-content/plugins/ultimate-social-media-icons/css/sfsi-sticky-footer.css/wp-content/plugins/ultimate-social-media-icons/css/sfsi-sticky-icons.css/wp-content/plugins/ultimate-social-media-icons/css/sfsi-widget.css/wp-content/plugins/ultimate-social-media-icons/css/style.css/wp-content/plugins/ultimate-social-media-icons/js/sfsi_commom.js/wp-content/plugins/ultimate-social-media-icons/js/sfsi_custom_social_sharing_data.js+4 more/wp-content/plugins/ultimate-social-media-icons/js/sfsi_commom.js/wp-content/plugins/ultimate-social-media-icons/js/sfsi_custom_social_sharing_data.js/wp-content/plugins/ultimate-social-media-icons/js/sfsi_float.js/wp-content/plugins/ultimate-social-media-icons/js/sfsi_frontpopUp.js/wp-content/plugins/ultimate-social-media-icons/js/sfsi_subscribe_widget.js/wp-content/plugins/ultimate-social-media-icons/js/sfsi_widget.jsultimate-social-media-icons/css/sfsi-landing-page.css?ver=ultimate-social-media-icons/css/sfsi-mobile.css?ver=ultimate-social-media-icons/css/sfsi-sticky-footer.css?ver=ultimate-social-media-icons/css/sfsi-sticky-icons.css?ver=ultimate-social-media-icons/css/sfsi-widget.css?ver=ultimate-social-media-icons/css/style.css?ver=ultimate-social-media-icons/js/sfsi_commom.js?ver=ultimate-social-media-icons/js/sfsi_custom_social_sharing_data.js?ver=ultimate-social-media-icons/js/sfsi_float.js?ver=ultimate-social-media-icons/js/sfsi_frontpopUp.js?ver=ultimate-social-media-icons/js/sfsi_subscribe_widget.js?ver=ultimate-social-media-icons/js/sfsi_widget.js?ver=HTML / DOM Fingerprints
sfsi_widgetsfsi_shortcode_containersfsi_wDivsfsi_main_content_containersfsi_social_plugin_containersfsi_actBGsfsi_actBG_boxsfsi_no_specific_alignment<!-- Comment for shuffle issue --><!-- IMPORTANT: If you are using elementor then you have to check the below option for loading of the CSS of the plugin -->data-idsfsi_widget_configsfsi_option_arr<div class="sfsi_widget sfsi_shortcode_container"><div id="sfsi_wDiv"></div>