Wanapost Several Social Sharing Security & Risk Analysis

wordpress.org/plugins/wanapost-several-social-sharing

Adds autopost to Wanapost.com and very attractive responsive social sharing buttons for social medias to wordpress posts, pages or media.

10 active installs v1.0 PHP + WP 3.5+ Updated Sep 8, 2016
responsive-social-buttonsresponsive-social-sharing-buttonswanapost-auto-pingwanapost-autopostwanapost-share
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wanapost Several Social Sharing Safe to Use in 2026?

Generally Safe

Score 85/100

Wanapost Several Social Sharing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The wanapost-several-social-sharing plugin, in version 1.0, exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities, doesn't perform external HTTP requests, uses prepared statements for all SQL queries, and its static analysis shows no critical or high severity taint flows. The attack surface appears limited, with only one shortcode identified as an entry point, and importantly, no unprotected AJAX handlers or REST API routes were found. This suggests a generally cautious approach to handling user input and API interactions.

However, significant concerns arise from the code analysis. A striking 92% of output is not properly escaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks, especially for the shortcode which acts as an entry point, is a major weakness. This means that authenticated users, even those with low privileges, could potentially trigger unintended actions or inject malicious scripts through the shortcode. While the plugin boasts no known CVEs and a clean vulnerability history, this can be misleading for a plugin with such poor output sanitization and lack of crucial security checks, as a vulnerability likely exists but has not been discovered or reported.

In conclusion, while the plugin avoids common pitfalls like unpatched CVEs and insecure SQL queries, the pervasive lack of output escaping and the absence of essential security checks on its sole entry point present a substantial risk. The high percentage of unescaped output strongly indicates a high likelihood of XSS vulnerabilities, and the missing nonce and capability checks could lead to privilege escalation or unauthorized actions. Users should exercise extreme caution, and developers should prioritize addressing these critical security gaps.

Key Concerns

  • High percentage of unescaped output (92%)
  • No nonce checks on entry points
  • No capability checks on entry points
  • File operations present
Vulnerabilities
None known

Wanapost Several Social Sharing Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Wanapost Several Social Sharing Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
190
17 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

8% escaped207 total outputs
Attack Surface

Wanapost Several Social Sharing Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wanapost-several-social-sharing] includes\class-public.php:13
WordPress Hooks 9
actionadmin_initincludes\class-admin.php:14
actionadmin_menuincludes\class-admin.php:15
filterplugin_action_links_wanapost-several-social-sharing/index.phpincludes\class-admin.php:17
actionadmin_enqueue_scriptsincludes\class-admin.php:20
actionpublish_postincludes\class-admin.php:102
actionpublish_pageincludes\class-admin.php:103
filterthe_contentincludes\class-public.php:11
actionwp_enqueue_scriptsincludes\class-public.php:12
filterthe_titleincludes\class-public.php:77
Maintenance & Trust

Wanapost Several Social Sharing Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedSep 8, 2016
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Wanapost Several Social Sharing Developer Profile

belaadel

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wanapost Several Social Sharing

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wanapost-several-social-sharing/static/admin-styles.css/wp-content/plugins/wanapost-several-social-sharing/static/social_share.css/wp-content/plugins/wanapost-several-social-sharing/static/socialshareadmin.js/wp-content/plugins/wanapost-several-social-sharing/static/socialshare.js
Script Paths
/wp-content/plugins/wanapost-several-social-sharing/static/socialshareadmin.js/wp-content/plugins/wanapost-several-social-sharing/static/socialshare.js
Version Parameters
wanapost-several-social-sharing/static/admin-styles.css?ver=wanapost-several-social-sharing/static/social_share.css?ver=wanapost-several-social-sharing/static/socialshareadmin.js?ver=wanapost-several-social-sharing/static/socialshare.js?ver=

HTML / DOM Fingerprints

JS Globals
WSSS_VERSIONWSSS_PLUGIN_DIRWSSS_PLUGIN_URL
Shortcode Output
[wanapost-several-social-sharing]
FAQ

Frequently Asked Questions about Wanapost Several Social Sharing