
All-in-one Like Widget Security & Risk Analysis
wordpress.org/plugins/all-in-one-facebook-like-widgetAll-in-one Like Widget. Lets you quickly add a Like Button, activity stream and/or a Fanbox to your WordPress site for your Facebook fanpage (as a wid …
Is All-in-one Like Widget Safe to Use in 2026?
Generally Safe
Score 92/100All-in-one Like Widget has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The static analysis of the 'all-in-one-facebook-like-widget' v2.2.9 plugin reveals a generally clean codebase in terms of entry points and dangerous functions. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events that could serve as direct attack vectors. Furthermore, the absence of dangerous function calls and the use of prepared statements for all SQL queries are positive security indicators. However, the plugin exhibits a significant concern with output escaping, where only 20% of outputs are properly handled. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, particularly given that XSS has been the common vulnerability type in its history.
The plugin has a history of one known CVE, which was a medium severity XSS vulnerability, reported recently. While this vulnerability is currently unpatched, the fact that there is only one known CVE and no critical or high severity issues reported is somewhat reassuring. However, the recurring pattern of XSS vulnerabilities, coupled with the poor output escaping identified in the static analysis, points to a consistent weakness in how the plugin handles user-provided data before displaying it on the frontend.
In conclusion, while the 'all-in-one-facebook-like-widget' plugin demonstrates strengths in its limited attack surface and secure database interactions, its substantial weakness in output escaping presents a considerable risk. The historical prevalence of XSS vulnerabilities reinforces this concern. Users should be aware of the potential for XSS attacks, and developers should prioritize addressing the identified output escaping issues to improve the plugin's overall security posture.
Key Concerns
- Poor output escaping (20% properly escaped)
- One known CVE (medium severity XSS)
All-in-one Like Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
All-in-one Like Widget <= 2.2.7 - Authenticated (Admin+) Stored Cross-Site Scripting
All-in-one Like Widget Release Timeline
All-in-one Like Widget Code Analysis
Output Escaping
All-in-one Like Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
All-in-one Like Widget Maintenance & Trust
Maintenance Signals
Community Trust
All-in-one Like Widget Alternatives
Easy Social Like Box – Popup – Sidebar Widget
cardoza-facebook-like-box
WP Facebook Like Box Plugin enables you to display the facebook page likes in sidebar widget or popup. Display like button for the posts.
Easy Social Box / Page Plugin
easy-facebook-like-box
Easy Social box display facebook like box. it enable Facebook Page owners to attract and gain Likes from their own website.
Profile Box Shortcode And Widget
facebook-likebox-widget-and-shortcode
A very easy and simple Facebook like box shortcode and widget plugin with mini profile, like Button, Share Button plugin For WordPress
Mongoose Page Plugin
facebook-page-feed-graph-api
The most popular way to display the Facebook Page Plugin on your WordPress website. Easy implementation using a shortcode or widget.
Social Like Box and Page by WpDevArt
like-box
WordPress Facebook Like box plugin will help you to display like box on your website, just add our plugin widget to your sidebar and use it.
All-in-one Like Widget Developer Profile
4 plugins · 6K total installs
How We Detect All-in-one Like Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
all-in-one-facebook-like-widget/aio-facebook-like-widget.php?ver=HTML / DOM Fingerprints
aio_facebook_like_widgetdata-hrefdata-widthdata-heightdata-tabsdata-hide-coverdata-show-facepile+1 more