
Popup Like box – Page Plugin Security & Risk Analysis
wordpress.org/plugins/ays-facebook-popup-likeboxWith the help of this amazing plugin you can promote your Facebook page and add number of Likes , which is very important today.
Is Popup Like box – Page Plugin Safe to Use in 2026?
Generally Safe
Score 92/100Popup Like box – Page Plugin has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "ays-facebook-popup-likebox" plugin v3.7.8 exhibits a mixed security posture. While it demonstrates some good practices like using prepared statements for the majority of its SQL queries and incorporating nonce and capability checks, significant concerns arise from its attack surface and output sanitization. A substantial portion of its AJAX handlers lack authentication checks, creating potential entry points for unauthorized actions. Furthermore, the taint analysis revealed a high-severity flow with unsanitized input, indicating a risk of vulnerabilities like Cross-Site Scripting (XSS) or SQL Injection if this input is not properly handled. The plugin's vulnerability history, with four known CVEs including a high-severity one, reinforces these concerns. The prevalence of XSS and SQL Injection vulnerabilities in the past suggests a recurring pattern of input sanitization issues, which is unfortunately echoed in the current code analysis.
While the absence of unpatched CVEs and the general use of prepared statements are positive indicators, the large number of unprotected AJAX endpoints and the identified unsanitized input flow are critical weaknesses. The low percentage of properly escaped output (31%) further exacerbates the XSS risk. The plugin's history of vulnerabilities, particularly in the past year, indicates a need for more rigorous security development practices to prevent similar issues from re-emerging. Overall, the plugin has areas of strength but requires immediate attention to address the identified security flaws and prevent exploitation.
Key Concerns
- 4 unprotected AJAX handlers
- High severity taint flow with unsanitized path
- 31% of outputs properly escaped
- 1 high severity CVE in history
- 3 medium severity CVEs in history
Popup Like box – Page Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Popup Like box <= 3.7.7 - Missing Authorization
Popup Like box – Page <= 3.7.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Popup Like box <= 3.6.0 - Reflected Cross-Site Scripting
Popup Like box – Page Plugin < 3.5.3 - SQL Injection
Popup Like box – Page Plugin <= 3.5.2 - Cross-Site Scripting
Popup Like box – Page Plugin Release Timeline
Popup Like box – Page Plugin Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Popup Like box – Page Plugin Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 16
Maintenance & Trust
Popup Like box – Page Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Popup Like box – Page Plugin Alternatives
Easy Social Like Box – Popup – Sidebar Widget
cardoza-facebook-like-box
WP Facebook Like Box Plugin enables you to display the facebook page likes in sidebar widget or popup. Display like button for the posts.
Profile Box Shortcode And Widget
facebook-likebox-widget-and-shortcode
A very easy and simple Facebook like box shortcode and widget plugin with mini profile, like Button, Share Button plugin For WordPress
Fan Page Widget by ThemeNcode
facebook-fan-page-widget
An widget that will display Facebook Fan page like box. Uses latest API of Facebook (v 16.0)
Mongoose Page Plugin
facebook-page-feed-graph-api
The most popular way to display the Facebook Page Plugin on your WordPress website. Easy implementation using a shortcode or widget.
Social Like Box and Page by WpDevArt
like-box
WordPress Facebook Like box plugin will help you to display like box on your website, just add our plugin widget to your sidebar and use it.
Popup Like box – Page Plugin Developer Profile
18 plugins · 111K total installs
How We Detect Popup Like box – Page Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ays-facebook-popup-likebox/public/css/lightbox.css/wp-content/plugins/ays-facebook-popup-likebox/public/css/popup.css/wp-content/plugins/ays-facebook-popup-likebox/public/css/style.css/wp-content/plugins/ays-facebook-popup-likebox/public/js/jquery.colorbox.js/wp-content/plugins/ays-facebook-popup-likebox/public/js/script.js/wp-content/plugins/ays-facebook-popup-likebox/public/js/jquery.colorbox.js/wp-content/plugins/ays-facebook-popup-likebox/public/js/script.jsays-facebook-popup-likebox/public/css/lightbox.css?ver=ays-facebook-popup-likebox/public/css/popup.css?ver=ays-facebook-popup-likebox/public/css/style.css?ver=ays-facebook-popup-likebox/public/js/jquery.colorbox.js?ver=ays-facebook-popup-likebox/public/js/script.js?ver=HTML / DOM Fingerprints
ays-notice-bannernavigation-barays-navigation-container-logo-upgrade-boxlogo-containerays-btn-upgradefpl-popup-container<!-- CSS
* WordPress Plugin Boilerplate constants
* @link https://www.w3.org/TR/PNG/
--><!-- End CSS --><!-- Script
* WordPress Plugin Boilerplate constants
* @link https://www.w3.org/TR/PNG/
--><!-- End Script -->+4 moredata-fpl-iddata-fpl-widthdata-fpl-heightdata-fpl-positiondata-fpl-delaydata-fpl-cookie+26 moreAYS_FPL_NAME_VERSIONAYS_FPL_NAMEAYS_FPL_ADMIN_URLAYS_FPL_PUBLIC_URLfpl_ajax_object[ays_facebook_popup_likebox]