
zhanzhangb-share Security & Risk Analysis
wordpress.org/plugins/zhanzhangb-share插件功能:支持微信分享:带缩略图与摘要、朋友圈分享带缩略图与摘要(均支持未认证公众号);QQ分享:带缩略图;QQ空间分享:带缩略图与摘要;微博分享:带缩略图与摘要;LinkedIn分享:带缩略图与摘要;邮件分享:调起系统默认邮箱客户端
Is zhanzhangb-share Safe to Use in 2026?
Generally Safe
Score 85/100zhanzhangb-share has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The zhanzhangb-share v1.0.0 plugin exhibits a generally good security posture due to the absence of known vulnerabilities and a significant effort to use prepared statements for SQL queries. The code analysis indicates a minimal attack surface, with no unprotected AJAX handlers or REST API routes. However, there are notable areas of concern. A critical aspect is the low percentage of properly escaped output (24%), which suggests a high likelihood of cross-site scripting (XSS) vulnerabilities if user-supplied data is not meticulously handled before being displayed. Additionally, the presence of a single taint flow with unsanitized paths, even without a critical or high severity rating, warrants attention as it indicates a potential vector for data manipulation or unauthorized access.
The plugin's vulnerability history is clear, showing no past CVEs, which is a positive sign suggesting a generally secure development history. However, the lack of past vulnerabilities does not guarantee future security, especially when combined with the identified code quality issues. The absence of nonce checks and a single capability check for its sole entry point (shortcode) could leave the plugin exposed if the shortcode's functionality is sensitive and not adequately protected against unauthorized invocation. While the plugin avoids dangerous functions and external HTTP requests to critical endpoints, the identified weaknesses in output escaping and the unsanitized path flow are the primary risks that need immediate attention.
Key Concerns
- Low percentage of properly escaped output
- Unsanitized path flow
- No nonce checks on entry points
zhanzhangb-share Security Vulnerabilities
zhanzhangb-share Code Analysis
Output Escaping
Data Flow Analysis
zhanzhangb-share Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
zhanzhangb-share Maintenance & Trust
Maintenance Signals
Community Trust
zhanzhangb-share Alternatives
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
themeisle-companion
Add modules like share buttons, header & footer scripts, disable comments, reading progress bar, custom fonts, custom login page & more in one plugin.
Social Media Share Buttons & Social Sharing Icons
ultimate-social-media-icons
Share buttons and pop up share icons for social media sharing
zhanzhangb-share Developer Profile
3 plugins · 2K total installs
How We Detect zhanzhangb-share
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zhanzhangb-share/zhanzhangb-share.css/wp-content/plugins/zhanzhangb-share/js/zhanzhangb_share.js/wp-content/plugins/zhanzhangb-share/js/qrcode.min.js/wp-content/plugins/zhanzhangb-share/jssdk.phpzhanzhangb-share/zhanzhangb-share.css?ver=zhanzhangb-share/js/zhanzhangb_share.js?ver=zhanzhangb-share/js/qrcode.min.js?ver=HTML / DOM Fingerprints
name="zhanzhangb_share_location"name="zhanzhangb_share_weixin_AppID"name="zhanzhangb_share_weixin_AppSecret"name="zhanzhangb_share_weibo_Appkey"name="zhanzhangb_share_weibo_uid"id="zhanzhangbqrcode"setShareInfoJSSDK[zhanzhangb_share]