WPJAM Social Share Security & Risk Analysis

wordpress.org/plugins/wpjam-social-share

社会化分享这个 WordPress 插件主要功能,就是在博客上集成当前国内主要社会化分享按钮,并且和 Google Analytics 深度整合。

10 active installs v1.0 PHP + WP 3.0+ Updated Feb 7, 2012
sharesocailwpjam
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPJAM Social Share Safe to Use in 2026?

Generally Safe

Score 85/100

WPJAM Social Share has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

Based on the static analysis, the wpjam-social-share plugin version 1.0 appears to have a strong security posture with zero identified entry points, dangerous functions, SQL queries without prepared statements, or file operations. The absence of identified taint flows further suggests a lack of exploitable vulnerabilities within the analyzed code.

However, a significant concern arises from the output escaping. With 100% of its 11 identified outputs not properly escaped, this presents a considerable risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is directly rendered on the frontend without proper sanitization could be manipulated to inject malicious scripts, potentially leading to session hijacking or other client-side attacks. The lack of nonce checks and capability checks also means that even if entry points were discovered in the future, their security might be compromised.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator of past security diligence or a limited attack surface that hasn't been targeted. Despite the clean history, the critical weakness in output escaping cannot be overlooked and requires immediate attention. The plugin shows good practices in avoiding dangerous functions and secure SQL queries, but the unescaped output is a major blind spot.

Key Concerns

  • 100% of outputs are not properly escaped
  • 0 nonces checked on entry points
  • 0 capability checks on entry points
Vulnerabilities
None known

WPJAM Social Share Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WPJAM Social Share Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped11 total outputs
Attack Surface

WPJAM Social Share Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_headwpjam_social_share.php:13
filterthe_contentwpjam_social_share.php:106
actioninitwpjam_social_share.php:136
Maintenance & Trust

WPJAM Social Share Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedFeb 7, 2012
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WPJAM Social Share Developer Profile

denishua

8 plugins · 4K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
143 days
View full developer profile
Detection Fingerprints

How We Detect WPJAM Social Share

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpjam-social-share/s.png/wp-content/plugins/wpjam-social-share/s32.png/wp-content/plugins/wpjam-social-share/shadow-center.png/wp-content/plugins/wpjam-social-share/shadow-side.png

HTML / DOM Fingerprints

CSS Classes
social-sharesocial-share-leftsocial-share-rightsocial-share-centershare-icon-wrappershare-shadow-wrappershare-iconshare-shadow+7 more
Data Attributes
data-sharedata-post-id
JS Globals
social_share
Shortcode Output
<div id="social-share"><p>分享到:</p><div class="social-share-left"></div><div class="social-share-center">
FAQ

Frequently Asked Questions about WPJAM Social Share