Uptolike Social Share Buttons Security & Risk Analysis

wordpress.org/plugins/uptolike-share

Uptolike Social Share Buttons - social bookmarking widget with sharing statistics.

5K active installs v1.5.9 PHP + WP 3.0.1+ Updated Nov 28, 2017
1addthisbookmarksocial-buttonsuptolike
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Uptolike Social Share Buttons Safe to Use in 2026?

Generally Safe

Score 85/100

Uptolike Social Share Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The uptolike-share plugin version 1.5.9 exhibits a generally good security posture based on the provided static analysis and vulnerability history. It avoids dangerous functions, uses prepared statements for all SQL queries, and has no known critical or high-severity vulnerabilities. The absence of external HTTP requests and bundled libraries also contributes positively to its security.

However, there are areas for improvement. The low percentage of properly escaped output (26%) is a significant concern, indicating a potential for cross-site scripting (XSS) vulnerabilities, especially given the presence of one taint flow with unsanitized paths, even if it was not classified as critical or high. The plugin also lacks nonce checks on its single entry point (a shortcode) and has only one capability check, suggesting that the entry point might not be adequately protected against unauthorized access or manipulation. The presence of a file operation is also noted, which warrants careful examination to ensure it's handled securely.

Overall, the plugin's strength lies in its lack of direct SQL injection risks and known historical vulnerabilities. The primary weaknesses stem from insufficient output escaping and potentially weak authentication/authorization for its shortcode. While no critical issues were flagged in the taint analysis, the combination of unsanitized paths and low output escaping creates a theoretical risk that should be addressed.

Key Concerns

  • Low output escaping percentage
  • Taint flow with unsanitized paths
  • No nonce checks on entry point
  • File operation detected
  • Limited capability checks
Vulnerabilities
None known

Uptolike Social Share Buttons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Uptolike Social Share Buttons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
6 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

26% escaped23 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
uptolike_create_admin_page (widget_options.php:88)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Uptolike Social Share Buttons Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[uptolike] widget_options.php:733
WordPress Hooks 14
filterplugin_action_linksuptolike_share_widget.php:19
filterplugin_row_metauptolike_share_widget.php:28
actionadmin_menuwidget_options.php:8
actionadmin_initwidget_options.php:9
actionwp_footerwidget_options.php:677
actionwp_footerwidget_options.php:680
actionwp_footerwidget_options.php:685
actionwp_footerwidget_options.php:690
actionwp_footerwidget_options.php:695
filterthe_contentwidget_options.php:703
actionwidgets_initwidget_options.php:948
actionadmin_noticeswidget_options.php:949
actionadmin_noticeswidget_options.php:950
actionadmin_menuwidget_options.php:951
Maintenance & Trust

Uptolike Social Share Buttons Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedNov 28, 2017
PHP min version
Downloads185K

Community Trust

Rating90/100
Number of ratings89
Active installs5K
Developer Profile

Uptolike Social Share Buttons Developer Profile

na1vez

1 plugin · 5K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Uptolike Social Share Buttons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/uptolike-share/js/main.js/wp-content/plugins/uptolike-share/css/uptolike_style.css
Script Paths
/wp-content/plugins/uptolike-share/js/main.js

HTML / DOM Fingerprints

CSS Classes
uptolike_site_urlnav-tab-activewrapper-tab
Data Attributes
data-src
JS Globals
getCodeuptolike_site_url
FAQ

Frequently Asked Questions about Uptolike Social Share Buttons