All-in-one Like Widget Security & Risk Analysis

wordpress.org/plugins/all-in-one-facebook-like-widget

All-in-one Like Widget. Lets you quickly add a Like Button, activity stream and/or a Fanbox to your WordPress site for your Facebook fanpage (as a wid …

1K active installs v2.2.9 PHP + WP 3.0+ Updated Apr 12, 2025
facebookfaceboxfanpagelike-boxlike-button
92
A · Safe
CVEs total1
Unpatched0
Last CVEApr 22, 2024
Safety Verdict

Is All-in-one Like Widget Safe to Use in 2026?

Generally Safe

Score 92/100

All-in-one Like Widget has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 22, 2024Updated 1yr ago
Risk Assessment

The static analysis of the 'all-in-one-facebook-like-widget' v2.2.9 plugin reveals a generally clean codebase in terms of entry points and dangerous functions. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events that could serve as direct attack vectors. Furthermore, the absence of dangerous function calls and the use of prepared statements for all SQL queries are positive security indicators. However, the plugin exhibits a significant concern with output escaping, where only 20% of outputs are properly handled. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, particularly given that XSS has been the common vulnerability type in its history.

The plugin has a history of one known CVE, which was a medium severity XSS vulnerability, reported recently. While this vulnerability is currently unpatched, the fact that there is only one known CVE and no critical or high severity issues reported is somewhat reassuring. However, the recurring pattern of XSS vulnerabilities, coupled with the poor output escaping identified in the static analysis, points to a consistent weakness in how the plugin handles user-provided data before displaying it on the frontend.

In conclusion, while the 'all-in-one-facebook-like-widget' plugin demonstrates strengths in its limited attack surface and secure database interactions, its substantial weakness in output escaping presents a considerable risk. The historical prevalence of XSS vulnerabilities reinforces this concern. Users should be aware of the potential for XSS attacks, and developers should prioritize addressing the identified output escaping issues to improve the plugin's overall security posture.

Key Concerns

  • Poor output escaping (20% properly escaped)
  • One known CVE (medium severity XSS)
Vulnerabilities
1 published

All-in-one Like Widget Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-32815medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

All-in-one Like Widget <= 2.2.7 - Authenticated (Admin+) Stored Cross-Site Scripting

Apr 22, 2024 Patched in 2.2.8 (8d)
Version History

All-in-one Like Widget Release Timeline

v2.2.9Current
v2.2.8
v2.2.71 CVE
v2.2.61 CVE
v2.2.51 CVE
v2.2.41 CVE
v2.2.31 CVE
v2.2.21 CVE
v2.2.11 CVE
v2.21 CVE
v2.11 CVE
v2.01 CVE
v1.41 CVE
Code Analysis
Analyzed Mar 16, 2026

All-in-one Like Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
40
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped50 total outputs
Attack Surface

All-in-one Like Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwidgets_initindex.php:25
actionwp_footerindex.php:94
Maintenance & Trust

All-in-one Like Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 12, 2025
PHP min version
Downloads61K

Community Trust

Rating98/100
Number of ratings7
Active installs1K
Developer Profile

All-in-one Like Widget Developer Profile

Jeroen Peters

4 plugins · 6K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
272 days
View full developer profile
Detection Fingerprints

How We Detect All-in-one Like Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
all-in-one-facebook-like-widget/aio-facebook-like-widget.php?ver=

HTML / DOM Fingerprints

CSS Classes
aio_facebook_like_widget
Data Attributes
data-hrefdata-widthdata-heightdata-tabsdata-hide-coverdata-show-facepile+1 more
FAQ

Frequently Asked Questions about All-in-one Like Widget