Popup Like box – Page Plugin Security & Risk Analysis

wordpress.org/plugins/ays-facebook-popup-likebox

With the help of this amazing plugin you can promote your Facebook page and add number of Likes , which is very important today.

100 active installs v3.7.8 PHP + WP 4.0+ Updated Feb 18, 2026
facebookfacebook-likefacebook-likeboxfacebook-page-promoterfacebook-popup-box
92
A · Safe
CVEs total5
Unpatched0
Last CVEMar 1, 2026
Safety Verdict

Is Popup Like box – Page Plugin Safe to Use in 2026?

Generally Safe

Score 92/100

Popup Like box – Page Plugin has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

5 known CVEsLast CVE: Mar 1, 2026Updated 2mo ago
Risk Assessment

The "ays-facebook-popup-likebox" plugin v3.7.8 exhibits a mixed security posture. While it demonstrates some good practices like using prepared statements for the majority of its SQL queries and incorporating nonce and capability checks, significant concerns arise from its attack surface and output sanitization. A substantial portion of its AJAX handlers lack authentication checks, creating potential entry points for unauthorized actions. Furthermore, the taint analysis revealed a high-severity flow with unsanitized input, indicating a risk of vulnerabilities like Cross-Site Scripting (XSS) or SQL Injection if this input is not properly handled. The plugin's vulnerability history, with four known CVEs including a high-severity one, reinforces these concerns. The prevalence of XSS and SQL Injection vulnerabilities in the past suggests a recurring pattern of input sanitization issues, which is unfortunately echoed in the current code analysis.

While the absence of unpatched CVEs and the general use of prepared statements are positive indicators, the large number of unprotected AJAX endpoints and the identified unsanitized input flow are critical weaknesses. The low percentage of properly escaped output (31%) further exacerbates the XSS risk. The plugin's history of vulnerabilities, particularly in the past year, indicates a need for more rigorous security development practices to prevent similar issues from re-emerging. Overall, the plugin has areas of strength but requires immediate attention to address the identified security flaws and prevent exploitation.

Key Concerns

  • 4 unprotected AJAX handlers
  • High severity taint flow with unsanitized path
  • 31% of outputs properly escaped
  • 1 high severity CVE in history
  • 3 medium severity CVEs in history
Vulnerabilities
5 published

Popup Like box – Page Plugin Security Vulnerabilities

CVEs by Year

2 CVEs in 2021
2021
1 CVE in 2022
2022
1 CVE in 2024
2024
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

High
1
Medium
4

5 total CVEs

CVE-2026-32428medium · 5.3Missing Authorization

Popup Like box <= 3.7.7 - Missing Authorization

Mar 1, 2026 Patched in 3.7.8 (46d)
CVE-2024-31387medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Popup Like box – Page <= 3.7.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

Apr 10, 2024 Patched in 3.7.3 (7d)
CVE-2022-0641medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Popup Like box <= 3.6.0 - Reflected Cross-Site Scripting

Mar 7, 2022 Patched in 3.6.1 (687d)
CVE-2021-24460high · 8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Popup Like box – Page Plugin < 3.5.3 - SQL Injection

Jun 29, 2021 Patched in 3.5.3 (938d)
WF-a713c7d3-06ce-4d65-9766-2b0331656ae6-ays-facebook-popup-likeboxmedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Popup Like box – Page Plugin <= 3.5.2 - Cross-Site Scripting

Jun 29, 2021 Patched in 3.5.3 (938d)
Version History

Popup Like box – Page Plugin Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Popup Like box – Page Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
10 prepared
Unescaped Output
343
157 escaped
Nonce Checks
5
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

91% prepared11 total queries

Output Escaping

31% escaped500 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

6 flows2 with unsanitized paths
deactivate_plugin_option_fb (admin\class-ays-facebook-popup-likebox-admin.php:259)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Popup Like box – Page Plugin Attack Surface

Entry Points5
Unprotected4

AJAX Handlers 4

authwp_ajax_deactivate_plugin_option_fbincludes\class-ays-facebook-popup-likebox.php:176
noprivwp_ajax_deactivate_plugin_option_fbincludes\class-ays-facebook-popup-likebox.php:177
authwp_ajax_ays_fpl_dismiss_buttonincludes\class-ays-facebook-popup-likebox.php:186
noprivwp_ajax_ays_fpl_dismiss_buttonincludes\class-ays-facebook-popup-likebox.php:187

Shortcodes 1

[ays_fb_popup_likebox] public\class-ays-facebook-popup-likebox-public.php:109
WordPress Hooks 16
filterset-screen-optionadmin\class-ays-facebook-popup-likebox-admin.php:55
actionplugins_loadedays-facebook-popup-likebox.php:70
actionadmin_noticesays-facebook-popup-likebox.php:88
actionplugins_loadedincludes\class-ays-facebook-popup-likebox.php:150
actionadmin_enqueue_scriptsincludes\class-ays-facebook-popup-likebox.php:165
actionadmin_enqueue_scriptsincludes\class-ays-facebook-popup-likebox.php:166
actionadmin_menuincludes\class-ays-facebook-popup-likebox.php:169
actionadmin_enqueue_scriptsincludes\class-ays-facebook-popup-likebox.php:178
actionadmin_enqueue_scriptsincludes\class-ays-facebook-popup-likebox.php:179
actionin_admin_footerincludes\class-ays-facebook-popup-likebox.php:181
actionadmin_noticesincludes\class-ays-facebook-popup-likebox.php:184
actioninitincludes\class-ays-facebook-popup-likebox.php:201
actionwp_footerincludes\class-ays-facebook-popup-likebox.php:202
actionwp_enqueue_scriptsincludes\class-ays-facebook-popup-likebox.php:203
actionwp_enqueue_scriptsincludes\class-ays-facebook-popup-likebox.php:204
actionadmin_noticesincludes\lists\class-fb-popup-likbox-list-table.php:13
Maintenance & Trust

Popup Like box – Page Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 18, 2026
PHP min version
Downloads31K

Community Trust

Rating100/100
Number of ratings4
Active installs100
Developer Profile

Popup Like box – Page Plugin Developer Profile

Ays Pro

18 plugins · 111K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
203 days
View full developer profile
Detection Fingerprints

How We Detect Popup Like box – Page Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ays-facebook-popup-likebox/public/css/lightbox.css/wp-content/plugins/ays-facebook-popup-likebox/public/css/popup.css/wp-content/plugins/ays-facebook-popup-likebox/public/css/style.css/wp-content/plugins/ays-facebook-popup-likebox/public/js/jquery.colorbox.js/wp-content/plugins/ays-facebook-popup-likebox/public/js/script.js
Script Paths
/wp-content/plugins/ays-facebook-popup-likebox/public/js/jquery.colorbox.js/wp-content/plugins/ays-facebook-popup-likebox/public/js/script.js
Version Parameters
ays-facebook-popup-likebox/public/css/lightbox.css?ver=ays-facebook-popup-likebox/public/css/popup.css?ver=ays-facebook-popup-likebox/public/css/style.css?ver=ays-facebook-popup-likebox/public/js/jquery.colorbox.js?ver=ays-facebook-popup-likebox/public/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
ays-notice-bannernavigation-barays-navigation-container-logo-upgrade-boxlogo-containerays-btn-upgradefpl-popup-container
HTML Comments
<!-- CSS * WordPress Plugin Boilerplate constants * @link https://www.w3.org/TR/PNG/ --><!-- End CSS --><!-- Script * WordPress Plugin Boilerplate constants * @link https://www.w3.org/TR/PNG/ --><!-- End Script -->+4 more
Data Attributes
data-fpl-iddata-fpl-widthdata-fpl-heightdata-fpl-positiondata-fpl-delaydata-fpl-cookie+26 more
JS Globals
AYS_FPL_NAME_VERSIONAYS_FPL_NAMEAYS_FPL_ADMIN_URLAYS_FPL_PUBLIC_URLfpl_ajax_object
Shortcode Output
[ays_facebook_popup_likebox]
FAQ

Frequently Asked Questions about Popup Like box – Page Plugin