WriteShare Writing Community Platform Security & Risk Analysis

wordpress.org/plugins/writeshare

WriteShare will turn WordPress into a full featured writing community, not just a blogging community. Site members can post books with chapters.

80 active installs v1.1.18 PHP + WP 4.4+ Updated Dec 31, 2018
bookschapterseducationfanfictionwriting-platform
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WriteShare Writing Community Platform Safe to Use in 2026?

Generally Safe

Score 85/100

WriteShare Writing Community Platform has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin 'writeshare' v1.1.18 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the plugin's reliance on prepared statements for SQL queries are significant strengths. Furthermore, the plugin demonstrates good practices in output escaping, with a high percentage of outputs being properly handled. The code analysis reveals no critical or high severity taint flows and a limited attack surface, with all identified entry points (shortcodes) appearing to have appropriate security checks based on the available data.

However, a key area of concern is the complete absence of nonce checks. While the static analysis doesn't explicitly show AJAX handlers or REST API routes that are *unprotected*, the general lack of nonce verification across the plugin could introduce vulnerabilities if new entry points are added or if existing ones are inadvertently exposed. The presence of 4 shortcodes with 0 unprotected entry points is positive, but the blanket absence of nonce checks is a notable weakness that warrants attention. The vulnerability history being clean is a very positive sign, suggesting a history of secure development or thorough auditing. The use of Select2 as a bundled library is common, but its specific version and any associated vulnerabilities would require further investigation if it were to become a concern.

In conclusion, 'writeshare' v1.1.18 appears to be a relatively secure plugin with good coding practices in place, particularly regarding SQL and output sanitization. The lack of historical vulnerabilities is a strong indicator of stability. The primary risk lies in the complete absence of nonce checks, which represents a potential weakness that could be exploited if not addressed. Developers should prioritize implementing nonce checks for all relevant entry points to further harden the plugin's security.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

WriteShare Writing Community Platform Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WriteShare Writing Community Platform Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
67 escaped
Nonce Checks
0
Capability Checks
7
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

88% escaped76 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<write> (templates\write.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WriteShare Writing Community Platform Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[wpws-template-profile] templates.php:62
[wpws-template-write] templates.php:86
[wpws-template-filters] templates.php:109
[wpws-content-meta] templates.php:123
WordPress Hooks 12
filtermap_meta_capcapabilities.php:47
actionadmin_menudashboard.php:38
actionedit_user_profiledashboard.php:58
actionprofile_updatedashboard.php:75
filterquery_varsroutes.php:59
actionparse_queryroutes.php:67
actionadmin_initsettings.php:43
filtertemplate_includetemplates.php:52
filterthe_excerpttemplates.php:132
filterthe_contenttemplates.php:147
actioninitwriteshare.php:70
actionplugins_loadedwriteshare.php:78
Maintenance & Trust

WriteShare Writing Community Platform Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedDec 31, 2018
PHP min version
Downloads18K

Community Trust

Rating96/100
Number of ratings18
Active installs80
Developer Profile

WriteShare Writing Community Platform Developer Profile

AOS

1 plugin · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WriteShare Writing Community Platform

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/writeshare/css/select2.min.css/wp-content/plugins/writeshare/js/select2.min.js
Script Paths
js/select2.min.js
Version Parameters
writeshare/css/select2.min.css?ver=writeshare/js/select2.min.js?ver=

HTML / DOM Fingerprints

Shortcode Output
[wpws-template-profile][wpws-template-write]
FAQ

Frequently Asked Questions about WriteShare Writing Community Platform