
WriteShare Writing Community Platform Security & Risk Analysis
wordpress.org/plugins/writeshareWriteShare will turn WordPress into a full featured writing community, not just a blogging community. Site members can post books with chapters.
Is WriteShare Writing Community Platform Safe to Use in 2026?
Generally Safe
Score 85/100WriteShare Writing Community Platform has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'writeshare' v1.1.18 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the plugin's reliance on prepared statements for SQL queries are significant strengths. Furthermore, the plugin demonstrates good practices in output escaping, with a high percentage of outputs being properly handled. The code analysis reveals no critical or high severity taint flows and a limited attack surface, with all identified entry points (shortcodes) appearing to have appropriate security checks based on the available data.
However, a key area of concern is the complete absence of nonce checks. While the static analysis doesn't explicitly show AJAX handlers or REST API routes that are *unprotected*, the general lack of nonce verification across the plugin could introduce vulnerabilities if new entry points are added or if existing ones are inadvertently exposed. The presence of 4 shortcodes with 0 unprotected entry points is positive, but the blanket absence of nonce checks is a notable weakness that warrants attention. The vulnerability history being clean is a very positive sign, suggesting a history of secure development or thorough auditing. The use of Select2 as a bundled library is common, but its specific version and any associated vulnerabilities would require further investigation if it were to become a concern.
In conclusion, 'writeshare' v1.1.18 appears to be a relatively secure plugin with good coding practices in place, particularly regarding SQL and output sanitization. The lack of historical vulnerabilities is a strong indicator of stability. The primary risk lies in the complete absence of nonce checks, which represents a potential weakness that could be exploited if not addressed. Developers should prioritize implementing nonce checks for all relevant entry points to further harden the plugin's security.
Key Concerns
- Missing nonce checks
WriteShare Writing Community Platform Security Vulnerabilities
WriteShare Writing Community Platform Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
WriteShare Writing Community Platform Attack Surface
Shortcodes 4
WordPress Hooks 12
Maintenance & Trust
WriteShare Writing Community Platform Maintenance & Trust
Maintenance Signals
Community Trust
WriteShare Writing Community Platform Alternatives
Classroom Library
classroom-library
Classroom library plugin to catalog books and create a check in/out system for students.
Tutor LMS – eLearning and online course solution
tutor
A complete WordPress LMS plugin to create any eLearning website easily.
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
learnpress
A WordPress LMS Plugin to create WordPress Learning Management System. Turn your WordPress to LMS WordPress Website with Courses, Lessons, Quizzes &am …
Interactive Content – H5P
h5p
Create and add rich content to your website for free. Some examples of what you get with H5P are Interactive Video, Quizzes, Collage and Timeline.
LearnPress – Course Review
learnpress-course-review
LearnPress Course Review - An extension plugin for LearnPress.
WriteShare Writing Community Platform Developer Profile
1 plugin · 80 total installs
How We Detect WriteShare Writing Community Platform
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/writeshare/css/select2.min.css/wp-content/plugins/writeshare/js/select2.min.jsjs/select2.min.jswriteshare/css/select2.min.css?ver=writeshare/js/select2.min.js?ver=HTML / DOM Fingerprints
[wpws-template-profile][wpws-template-write]