
Yet Another Social Plugin Security & Risk Analysis
wordpress.org/plugins/yet-another-social-pluginAdd social networking share buttons above or below each posts. Easy customization and positioning of the buttons in the Options page.
Is Yet Another Social Plugin Safe to Use in 2026?
Generally Safe
Score 85/100Yet Another Social Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of yet-another-social-plugin v1.3 indicates a generally good security posture in terms of potential attack vectors. The absence of AJAX handlers, REST API routes, shortcodes, and cron events, particularly those without authentication or permission checks, significantly limits the plugin's attack surface. Furthermore, the complete reliance on prepared statements for SQL queries is a strong indicator of secure database interaction, and there are no reported external HTTP requests or file operations, which often present security risks. The lack of any critical or high-severity taint flows also suggests that user-supplied data is not being mishandled in a way that would lead to common vulnerabilities like injection attacks.
However, the analysis reveals a critical concern regarding output escaping. With 100% of the five identified outputs lacking proper escaping, this plugin is highly vulnerable to Cross-Site Scripting (XSS) attacks. Any dynamic data rendered by the plugin without sanitization could be exploited by attackers to inject malicious scripts into the pages where the plugin is active. This is a significant weakness that overshadows the plugin's strengths in other areas. The vulnerability history shows no past issues, which is positive, but it does not mitigate the current, actively identified XSS risk. Therefore, while the plugin has a small attack surface and secure database practices, the severe lack of output escaping presents a clear and present danger.
Key Concerns
- All outputs are unescaped
Yet Another Social Plugin Security Vulnerabilities
Yet Another Social Plugin Code Analysis
Output Escaping
Yet Another Social Plugin Attack Surface
WordPress Hooks 7
Maintenance & Trust
Yet Another Social Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Yet Another Social Plugin Alternatives
Easy Social Box / Page Plugin
easy-facebook-like-box
Easy Social box display facebook like box. it enable Facebook Page owners to attract and gain Likes from their own website.
FireCask Like & Share Button
facebook-like-send-button
Insert the Facebook Like and/or Send button to any post, page or template with this simple plugin. Also lets you add them via shortcode anywhere in yo …
RA-Socialize Button
ra-socialize-button
RA-Socialize Button adds a Google+, twitter and facebook button to your blog post.
Easy Embed Page Widget
embed-page-facebook
This is widget of showing Facebook page embedded in your website.short code [embed_facebook]
Social Media Feather | social media sharing
social-media-feather
Lightweight, modern looking and effective social media sharing and profile buttons and icons. All your social media needs in 1 easy package!
Yet Another Social Plugin Developer Profile
4 plugins · 650 total installs
How We Detect Yet Another Social Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yet-another-social-plugin/css/yasp-styles.css/wp-content/plugins/yet-another-social-plugin/js/yasp-scripts.js/wp-content/plugins/yet-another-social-plugin/js/yasp-scripts.jsyet-another-social-plugin/css/yasp-styles.css?ver=yet-another-social-plugin/js/yasp-scripts.js?ver=HTML / DOM Fingerprints
yasp-buttons-wrappername="yasp_options[chek_button1]"name="yasp_options[chk_button1]"name="yasp_options[hide_button]"name="yasp_options[txt_one]"name="yasp_options[chk_button2]"name="yasp_options[chk_default_options_db]"