
WP-Social-Share-Privacy Security & Risk Analysis
wordpress.org/plugins/wp-social-share-privacy-pluginWordpress-Plugin Umsetzung des jQuery Plug-In socialshareprivacy von heise.de
Is WP-Social-Share-Privacy Safe to Use in 2026?
Generally Safe
Score 85/100WP-Social-Share-Privacy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'wp-social-share-privacy-plugin' version 1.1.6 exhibits a mixed security posture. On the positive side, there are no reported CVEs, indicating a history of stability or lack of significant public vulnerabilities. The static analysis also shows no dangerous functions, no raw SQL queries, no file operations, no external HTTP requests, and no taint flows, all of which are strong indicators of good security practices. The absence of AJAX handlers, REST API routes, and shortcodes also means a very limited attack surface.
However, a significant concern arises from the output escaping. With 59 total outputs and 0% properly escaped, this presents a critical risk. This means that any user-supplied data that is outputted by the plugin is highly susceptible to cross-site scripting (XSS) attacks. While there are capability checks present, the lack of proper output escaping leaves the door wide open for attackers to inject malicious scripts, potentially compromising user sessions or defacing the website. The absence of nonce checks, while not directly tied to an attack surface, further compounds the risk by not implementing a standard security measure for form submissions or actions.
In conclusion, despite a clean vulnerability history and a small attack surface, the complete lack of output escaping is a severe flaw that significantly undermines the plugin's security. This makes it a high-risk plugin for deployment in any environment where user input is handled or displayed. The plugin demonstrates strengths in areas like SQL handling and a limited attack surface but critically fails in output sanitization.
Key Concerns
- Output is not properly escaped
- No nonce checks
WP-Social-Share-Privacy Security Vulnerabilities
WP-Social-Share-Privacy Code Analysis
Output Escaping
WP-Social-Share-Privacy Attack Surface
WordPress Hooks 8
Maintenance & Trust
WP-Social-Share-Privacy Maintenance & Trust
Maintenance Signals
Community Trust
WP-Social-Share-Privacy Alternatives
2-Klicks-Button – Socialshareprivacy Plugin
2-klicks-button-socialshareprivacy-plugin
Wordpress-Plugin Umsetzung des 2-Klick-Button Scripts von heise.de Datenschutz freundliche Social-Media-Einbindung von Facebook, Twitter und Google+.
Simple Social – Sharing Widgets & Icons Updated
simple-social-sharing-widgets-icons-updated
Adds a set of cool icons and widgets at the end of your post for your readers to share.
El club de la Noticia
el-club-de-la-noticia
English
WP socialshareprivacy
wp-socialshareprivacy
Datenschutzfreundliche Social-Media-Einbindung (Facebook, Twitter und Google+)
WP Ya Share
wp-ya-share
Adds the Yandex 'Share in social networks' block into posts or widget to simplify saving URLs of your blog pages into social networks.
WP-Social-Share-Privacy Developer Profile
1 plugin · 10 total installs
How We Detect WP-Social-Share-Privacy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-social-share-privacy-plugin/js/socialshareprivacy.min.js/wp-content/plugins/wp-social-share-privacy-plugin/css/style.css/wp-content/plugins/wp-social-share-privacy-plugin/css/socialshareprivacy.css/wp-content/plugins/wp-social-share-privacy-plugin/js/socialshareprivacy.min.jswp-social-share-privacy-plugin/js/socialshareprivacy.min.js?ver=wp-social-share-privacy-plugin/css/style.css?ver=wp-social-share-privacy-plugin/css/socialshareprivacy.css?ver=HTML / DOM Fingerprints
socialshareprivacy_boxsocialSharePrivacy