
Wanapost Several Social Sharing Security & Risk Analysis
wordpress.org/plugins/wanapost-several-social-sharingAdds autopost to Wanapost.com and very attractive responsive social sharing buttons for social medias to wordpress posts, pages or media.
Is Wanapost Several Social Sharing Safe to Use in 2026?
Generally Safe
Score 85/100Wanapost Several Social Sharing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wanapost-several-social-sharing plugin, in version 1.0, exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities, doesn't perform external HTTP requests, uses prepared statements for all SQL queries, and its static analysis shows no critical or high severity taint flows. The attack surface appears limited, with only one shortcode identified as an entry point, and importantly, no unprotected AJAX handlers or REST API routes were found. This suggests a generally cautious approach to handling user input and API interactions.
However, significant concerns arise from the code analysis. A striking 92% of output is not properly escaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks, especially for the shortcode which acts as an entry point, is a major weakness. This means that authenticated users, even those with low privileges, could potentially trigger unintended actions or inject malicious scripts through the shortcode. While the plugin boasts no known CVEs and a clean vulnerability history, this can be misleading for a plugin with such poor output sanitization and lack of crucial security checks, as a vulnerability likely exists but has not been discovered or reported.
In conclusion, while the plugin avoids common pitfalls like unpatched CVEs and insecure SQL queries, the pervasive lack of output escaping and the absence of essential security checks on its sole entry point present a substantial risk. The high percentage of unescaped output strongly indicates a high likelihood of XSS vulnerabilities, and the missing nonce and capability checks could lead to privilege escalation or unauthorized actions. Users should exercise extreme caution, and developers should prioritize addressing these critical security gaps.
Key Concerns
- High percentage of unescaped output (92%)
- No nonce checks on entry points
- No capability checks on entry points
- File operations present
Wanapost Several Social Sharing Security Vulnerabilities
Wanapost Several Social Sharing Code Analysis
Output Escaping
Wanapost Several Social Sharing Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Wanapost Several Social Sharing Maintenance & Trust
Maintenance Signals
Community Trust
Wanapost Several Social Sharing Alternatives
Wanapost Several Social Sharing Developer Profile
1 plugin · 10 total installs
How We Detect Wanapost Several Social Sharing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wanapost-several-social-sharing/static/admin-styles.css/wp-content/plugins/wanapost-several-social-sharing/static/social_share.css/wp-content/plugins/wanapost-several-social-sharing/static/socialshareadmin.js/wp-content/plugins/wanapost-several-social-sharing/static/socialshare.js/wp-content/plugins/wanapost-several-social-sharing/static/socialshareadmin.js/wp-content/plugins/wanapost-several-social-sharing/static/socialshare.jswanapost-several-social-sharing/static/admin-styles.css?ver=wanapost-several-social-sharing/static/social_share.css?ver=wanapost-several-social-sharing/static/socialshareadmin.js?ver=wanapost-several-social-sharing/static/socialshare.js?ver=HTML / DOM Fingerprints
WSSS_VERSIONWSSS_PLUGIN_DIRWSSS_PLUGIN_URL[wanapost-several-social-sharing]