
Uptolike Social Share Buttons Security & Risk Analysis
wordpress.org/plugins/uptolike-shareUptolike Social Share Buttons - social bookmarking widget with sharing statistics.
Is Uptolike Social Share Buttons Safe to Use in 2026?
Generally Safe
Score 85/100Uptolike Social Share Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The uptolike-share plugin version 1.5.9 exhibits a generally good security posture based on the provided static analysis and vulnerability history. It avoids dangerous functions, uses prepared statements for all SQL queries, and has no known critical or high-severity vulnerabilities. The absence of external HTTP requests and bundled libraries also contributes positively to its security.
However, there are areas for improvement. The low percentage of properly escaped output (26%) is a significant concern, indicating a potential for cross-site scripting (XSS) vulnerabilities, especially given the presence of one taint flow with unsanitized paths, even if it was not classified as critical or high. The plugin also lacks nonce checks on its single entry point (a shortcode) and has only one capability check, suggesting that the entry point might not be adequately protected against unauthorized access or manipulation. The presence of a file operation is also noted, which warrants careful examination to ensure it's handled securely.
Overall, the plugin's strength lies in its lack of direct SQL injection risks and known historical vulnerabilities. The primary weaknesses stem from insufficient output escaping and potentially weak authentication/authorization for its shortcode. While no critical issues were flagged in the taint analysis, the combination of unsanitized paths and low output escaping creates a theoretical risk that should be addressed.
Key Concerns
- Low output escaping percentage
- Taint flow with unsanitized paths
- No nonce checks on entry point
- File operation detected
- Limited capability checks
Uptolike Social Share Buttons Security Vulnerabilities
Uptolike Social Share Buttons Code Analysis
Output Escaping
Data Flow Analysis
Uptolike Social Share Buttons Attack Surface
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
Uptolike Social Share Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Uptolike Social Share Buttons Alternatives
Sharekoube
sharekoube
Add to Sharedaddy support service.
Redirection
redirection
Manage 301 redirects, track 404 errors, and improve your site. No knowledge of Apache or Nginx required.
Loco Translate
loco-translate
Translate WordPress plugins and themes directly in your browser. Versatile PO file editor with integrated AI translation providers.
WP Multibyte Patch
wp-multibyte-patch
Multibyte functionality enhancement for the WordPress Japanese package.
Ally – Web Accessibility & Usability
pojo-accessibility
Ally: Make your site more inclusive by scanning for accessibility violations, fixing them easily, and adding a usability widget and accessibility stat …
Uptolike Social Share Buttons Developer Profile
1 plugin · 5K total installs
How We Detect Uptolike Social Share Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/uptolike-share/js/main.js/wp-content/plugins/uptolike-share/css/uptolike_style.css/wp-content/plugins/uptolike-share/js/main.jsHTML / DOM Fingerprints
uptolike_site_urlnav-tab-activewrapper-tabdata-srcgetCodeuptolike_site_url