
All-in-one Like Widget Security & Risk Analysis
wordpress.org/plugins/all-in-one-facebook-like-widgetAll-in-one Like Widget for your Facebook page. Quickly add a Like button, activity stream and/or a Fanbox in a widget.
Is All-in-one Like Widget Safe to Use in 2026?
Generally Safe
Score 100/100All-in-one Like Widget has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The static analysis of the 'all-in-one-facebook-like-widget' v2.2.9 plugin reveals a generally clean codebase in terms of entry points and dangerous functions. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events that could serve as direct attack vectors. Furthermore, the absence of dangerous function calls and the use of prepared statements for all SQL queries are positive security indicators. However, the plugin exhibits a significant concern with output escaping, where only 20% of outputs are properly handled. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, particularly given that XSS has been the common vulnerability type in its history.
The plugin has a history of one known CVE, which was a medium severity XSS vulnerability, reported recently. While this vulnerability is currently unpatched, the fact that there is only one known CVE and no critical or high severity issues reported is somewhat reassuring. However, the recurring pattern of XSS vulnerabilities, coupled with the poor output escaping identified in the static analysis, points to a consistent weakness in how the plugin handles user-provided data before displaying it on the frontend.
In conclusion, while the 'all-in-one-facebook-like-widget' plugin demonstrates strengths in its limited attack surface and secure database interactions, its substantial weakness in output escaping presents a considerable risk. The historical prevalence of XSS vulnerabilities reinforces this concern. Users should be aware of the potential for XSS attacks, and developers should prioritize addressing the identified output escaping issues to improve the plugin's overall security posture.
Key Concerns
- Poor output escaping (20% properly escaped)
- One known CVE (medium severity XSS)
All-in-one Like Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
All-in-one Like Widget <= 2.2.7 - Authenticated (Admin+) Stored Cross-Site Scripting
All-in-one Like Widget Release Timeline
All-in-one Like Widget Code Analysis
Output Escaping
All-in-one Like Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
All-in-one Like Widget Maintenance & Trust
Maintenance Signals
Community Trust
All-in-one Like Widget Alternatives
Easy Social Like Box – Popup – Sidebar Widget
cardoza-facebook-like-box
WP Facebook Like Box Plugin enables you to display the facebook page likes in sidebar widget or popup. Display like button for the posts.
Easy Social Box / Page Plugin
easy-facebook-like-box
Easy Social box display facebook like box. it enable Facebook Page owners to attract and gain Likes from their own website.
Profile Box Shortcode And Widget
facebook-likebox-widget-and-shortcode
A very easy and simple Facebook like box shortcode and widget plugin with mini profile, like Button, Share Button plugin For WordPress
FireCask Like & Share Button
facebook-like-send-button
Insert the Facebook Like and/or Send button to any post, page or template with this simple plugin. Also lets you add them via shortcode anywhere in yo …
RA-Socialize Button
ra-socialize-button
RA-Socialize Button adds a Google+, twitter and facebook button to your blog post.
All-in-one Like Widget Developer Profile
4 plugins · 6K total installs
How We Detect All-in-one Like Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
all-in-one-facebook-like-widget/aio-facebook-like-widget.php?ver=HTML / DOM Fingerprints
aio_facebook_like_widgetdata-hrefdata-widthdata-heightdata-tabsdata-hide-coverdata-show-facepile+1 more