Social Share Buttons & Analytics Plugin – GetSocial.io Security & Risk Analysis

wordpress.org/plugins/wp-share-buttons-analytics-by-getsocial

Free share buttons for 30+ of your favorite social networks. Increase traffic through social sharing with GetSocial buttons.

2K active installs v4.5 PHP 5.2.4+ WP 3.0+ Updated Apr 30, 2024
shareshare-buttonssocial-analyticssocial-mediasocial-sharing
69
C · Use Caution
CVEs total2
Unpatched1
Last CVEApr 4, 2025
Safety Verdict

Is Social Share Buttons & Analytics Plugin – GetSocial.io Safe to Use in 2026?

Use With Caution

Score 69/100

Social Share Buttons & Analytics Plugin – GetSocial.io has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

2 known CVEs 1 unpatched Last CVE: Apr 4, 2025Updated 1yr ago
Risk Assessment

The "wp-share-buttons-analytics-by-getsocial" plugin v4.5 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a single nonce check, significant concerns arise from its attack surface and vulnerability history. Three AJAX handlers lack authentication checks, creating a considerable risk for unauthorized actions. The low percentage of properly escaped output (4%) is also a major red flag, suggesting a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, which aligns with its past vulnerability types.

The plugin's history of two known CVEs, one of which remains unpatched, and both being of medium severity, further amplifies the risk. The prevalence of "Missing Authorization" and "Cross-site Scripting" in its vulnerability types directly correlates with the static analysis findings of unprotected AJAX handlers and poor output escaping. This suggests a recurring pattern of security weaknesses that have not been fully addressed.

In conclusion, while the plugin avoids certain common pitfalls like raw SQL queries and file operations, the unprotected AJAX endpoints and the high proportion of improperly escaped output, coupled with a history of medium-severity vulnerabilities including XSS, present a substantial security risk. The unpatched CVE is particularly concerning, leaving users exposed to known exploits.

Key Concerns

  • Unprotected AJAX handlers
  • Low percentage of properly escaped output
  • 1 unpatched CVE (medium severity)
  • History of XSS vulnerabilities
  • History of Missing Authorization vulnerabilities
Vulnerabilities
2

Social Share Buttons & Analytics Plugin – GetSocial.io Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-32239medium · 4.3Missing Authorization

Social Share Buttons & Analytics Plugin – GetSocial.io <= 4.5 - Missing Authorization

Apr 4, 2025Unpatched
CVE-2023-49189medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Social Share Buttons & Analytics Plugin – GetSocial.io <= 4.3.12 - Authenticated (Administrator+) Stored Cross-Site Scripting

Nov 29, 2023 Patched in 4.4 (55d)
Code Analysis
Analyzed Mar 16, 2026

Social Share Buttons & Analytics Plugin – GetSocial.io Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
54
2 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

4% escaped56 total outputs
Attack Surface
3 unprotected

Social Share Buttons & Analytics Plugin – GetSocial.io Attack Surface

Entry Points4
Unprotected3

AJAX Handlers 3

authwp_ajax_gs_updatewp-share-buttons-analytics-getsocial.php:37
authwp_ajax_gs_update_with_valueswp-share-buttons-analytics-getsocial.php:38
authwp_ajax_save_popup_visitwp-share-buttons-analytics-getsocial.php:475

Shortcodes 1

[getsocial] wp-share-buttons-analytics-getsocial.php:330
WordPress Hooks 9
actionadmin_menuwp-share-buttons-analytics-getsocial.php:15
actionadmin_initwp-share-buttons-analytics-getsocial.php:28
actionwp_headwp-share-buttons-analytics-getsocial.php:91
filterthe_contentwp-share-buttons-analytics-getsocial.php:103
filterthe_contentwp-share-buttons-analytics-getsocial.php:105
filterthe_excerptwp-share-buttons-analytics-getsocial.php:108
actionadd_meta_boxeswp-share-buttons-analytics-getsocial.php:370
actionsave_postwp-share-buttons-analytics-getsocial.php:448
actionadmin_enqueue_scriptswp-share-buttons-analytics-getsocial.php:473
Maintenance & Trust

Social Share Buttons & Analytics Plugin – GetSocial.io Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 30, 2024
PHP min version5.2.4
Downloads533K

Community Trust

Rating88/100
Number of ratings154
Active installs2K
Developer Profile

Social Share Buttons & Analytics Plugin – GetSocial.io Developer Profile

Joao Romao

1 plugin · 2K total installs

66
trust score
Avg Security Score
69/100
Avg Patch Time
55 days
View full developer profile
Detection Fingerprints

How We Detect Social Share Buttons & Analytics Plugin – GetSocial.io

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-share-buttons-analytics-by-getsocial/css/style.css/wp-content/plugins/wp-share-buttons-analytics-by-getsocial/css/social-share-buttons.css/wp-content/plugins/wp-share-buttons-analytics-by-getsocial/js/social-share-buttons.js/wp-content/plugins/wp-share-buttons-analytics-by-getsocial/lib/gs.js
Script Paths
/wp-content/plugins/wp-share-buttons-analytics-by-getsocial/js/social-share-buttons.js/wp-content/plugins/wp-share-buttons-analytics-by-getsocial/lib/gs.js
Version Parameters
/wp-content/plugins/wp-share-buttons-analytics-by-getsocial/css/style.css?ver=/wp-content/plugins/wp-share-buttons-analytics-by-getsocial/css/social-share-buttons.css?ver=/wp-content/plugins/wp-share-buttons-analytics-by-getsocial/js/social-share-buttons.js?ver=/wp-content/plugins/wp-share-buttons-analytics-by-getsocial/lib/gs.js?ver=

HTML / DOM Fingerprints

CSS Classes
gs-social-sharegs-social-share-buttonsgs-social-icongs-btn-largegs-btn-mediumgs-btn-smallgs-btn-countergs-btn-icon+5 more
HTML Comments
<!-- GetSocial.io script --><!-- GetSocial.io share buttons -->
Data Attributes
data-getsocial-share-urldata-getsocial-share-titledata-getsocial-share-imagedata-getsocial-widget-iddata-getsocial-typedata-getsocial-theme+5 more
JS Globals
window.GetSocialvar GS
Shortcode Output
[getsocial]
FAQ

Frequently Asked Questions about Social Share Buttons & Analytics Plugin – GetSocial.io