
Easy Social Like Box – Popup – Sidebar Widget Security & Risk Analysis
wordpress.org/plugins/cardoza-facebook-like-boxWP Facebook Like Box Plugin enables you to display the facebook page likes in sidebar widget or popup. Display like button for the posts.
Is Easy Social Like Box – Popup – Sidebar Widget Safe to Use in 2026?
Generally Safe
Score 90/100Easy Social Like Box – Popup – Sidebar Widget has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "cardoza-facebook-like-box" plugin v4.8 exhibits a mixed security posture. On the positive side, static analysis reveals no direct critical or high-severity vulnerabilities in the current codebase, with a good percentage of output escaping and all SQL queries using prepared statements. The absence of dangerous functions, file operations, and external HTTP requests is also encouraging. However, the presence of two known CVEs in its history, including a past high-severity vulnerability, is a significant concern, suggesting a potential for recurring security weaknesses. While no CVEs are currently unpatched, the history of past vulnerabilities, particularly Cross-Site Scripting (XSS), indicates a need for ongoing vigilance and thorough code reviews by the developers. The limited attack surface with only two shortcodes, and zero unprotected entry points, is a positive aspect, but past vulnerabilities suggest that the sanitization or escaping logic might have been insufficient in previous versions.
In conclusion, while the current version of "cardoza-facebook-like-box" appears to have addressed immediate critical threats based on the static analysis, its historical vulnerability pattern, specifically the past high-severity XSS, warrants a cautious approach. Users should prioritize ensuring they are on the latest patched version and be aware that plugins with a history of vulnerabilities may require more frequent updates and monitoring. The developers have shown improvement in handling SQL and output escaping, but the past incident indicates a potential for subtle vulnerabilities to be introduced.
Key Concerns
- Past high severity vulnerability
- Past medium severity vulnerability
- 82% output escaping is good, but 18% is not
Easy Social Like Box – Popup – Sidebar Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Easy Social Like Box – Popup – Sidebar Widget <= 4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Easy Social Like Box – Popup – Sidebar Widget < 2.8.3 - Cross-Site Scripting
Easy Social Like Box – Popup – Sidebar Widget Release Timeline
Easy Social Like Box – Popup – Sidebar Widget Code Analysis
Output Escaping
Data Flow Analysis
Easy Social Like Box – Popup – Sidebar Widget Attack Surface
Shortcodes 2
WordPress Hooks 12
Maintenance & Trust
Easy Social Like Box – Popup – Sidebar Widget Maintenance & Trust
Maintenance Signals
Community Trust
Easy Social Like Box – Popup – Sidebar Widget Alternatives
Easy Social Box / Page Plugin
easy-facebook-like-box
Easy Social box display facebook like box. it enable Facebook Page owners to attract and gain Likes from their own website.
Profile Box Shortcode And Widget
facebook-likebox-widget-and-shortcode
A very easy and simple Facebook like box shortcode and widget plugin with mini profile, like Button, Share Button plugin For WordPress
Fan Page Widget by ThemeNcode
facebook-fan-page-widget
An widget that will display Facebook Fan page like box. Uses latest API of Facebook (v 16.0)
CB Social Like Box
cb-facebook-like-box
Easy facebook like box in sidebar WordPress site. go to appearance>widget>use 'Social Like Widget'
Mongoose Page Plugin
facebook-page-feed-graph-api
The most popular way to display the Facebook Page Plugin on your WordPress website. Easy implementation using a shortcode or widget.
Easy Social Like Box – Popup – Sidebar Widget Developer Profile
1 plugin · 7K total installs
How We Detect Easy Social Like Box – Popup – Sidebar Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cardoza-facebook-like-box/admin_cardozafacebook.css/wp-content/plugins/cardoza-facebook-like-box/admin_cardozafacebook.js/wp-content/plugins/cardoza-facebook-like-box/cardozafacebook.css/wp-content/plugins/cardoza-facebook-like-box/cardozafacebook.js/wp-content/plugins/cardoza-facebook-like-box/cardozafacebook_popup.css/wp-content/plugins/cardoza-facebook-like-box/admin_cardozafacebook.js/wp-content/plugins/cardoza-facebook-like-box/cardozafacebook.jsHTML / DOM Fingerprints
cardoza-facebook-like-box[cardoza_facebook_like_box][cardoza_facebook_posts_like]