WP Ya Share Security & Risk Analysis

wordpress.org/plugins/wp-ya-share

Adds the Yandex 'Share in social networks' block into posts or widget to simplify saving URLs of your blog pages into social networks.

200 active installs v1.6.1 PHP + WP 2.8.6+ Updated Dec 14, 2014
bookmarksfacebooksharesocialtwitter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Ya Share Safe to Use in 2026?

Generally Safe

Score 85/100

WP Ya Share has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The static analysis of wp-ya-share v1.6.1 reveals a promising security posture in several key areas. The absence of any identified dangerous functions, SQL queries that are fully prepared, and no observed file operations or external HTTP requests are significant strengths. Furthermore, the plugin has no known CVEs, indicating a history of stability and likely diligent security practices by the developers. The very limited attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, further minimizes potential exploitation vectors.

However, a notable concern arises from the output escaping, where only 11% of outputs are properly escaped. This significantly increases the risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data or dynamic content could be injected and executed in a user's browser without proper sanitization. The complete absence of nonce checks and capability checks is also a significant weakness, especially if any of the entry points were to be discovered or introduced in future versions, as it leaves them open to unauthorized actions. The lack of taint analysis flows being analyzed could mean potential vulnerabilities remain undetected.

In conclusion, while the plugin benefits from a clean history and a minimal attack surface with strong practices around SQL and external interactions, the poor output escaping and lack of authentication checks on entry points are critical areas for immediate attention. Addressing these weaknesses is essential to fortify the plugin's security and prevent common web vulnerabilities.

Key Concerns

  • Low percentage of properly escaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

WP Ya Share Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Ya Share Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

11% escaped19 total outputs
Attack Surface

WP Ya Share Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_initwp-ya-share.php:40
actionwp_enqueue_scriptswp-ya-share.php:156
filterthe_contentwp-ya-share.php:180
actionadmin_menuwp-ya-share.php:328
actionwidgets_initwp-ya-share.php:371
actionadmin_enqueue_scriptswp-ya-share.php:373
Maintenance & Trust

WP Ya Share Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedDec 14, 2014
PHP min version
Downloads25K

Community Trust

Rating80/100
Number of ratings4
Active installs200
Developer Profile

WP Ya Share Developer Profile

andreykashops

7 plugins · 2K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Ya Share

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP Ya Share