Easy Social Like Box – Popup – Sidebar Widget Security & Risk Analysis

wordpress.org/plugins/cardoza-facebook-like-box

WP Facebook Like Box Plugin enables you to display the facebook page likes in sidebar widget or popup. Display like button for the posts.

7K active installs v4.8 PHP 7.2+ WP 5.0+ Updated May 14, 2025
facebook-likefacebook-like-boxfacebook-likeboxfb-like-boxlike-button
90
A · Safe
CVEs total2
Unpatched0
Last CVEJun 5, 2024
Safety Verdict

Is Easy Social Like Box – Popup – Sidebar Widget Safe to Use in 2026?

Generally Safe

Score 90/100

Easy Social Like Box – Popup – Sidebar Widget has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Jun 5, 2024Updated 1yr ago
Risk Assessment

The "cardoza-facebook-like-box" plugin v4.8 exhibits a mixed security posture. On the positive side, static analysis reveals no direct critical or high-severity vulnerabilities in the current codebase, with a good percentage of output escaping and all SQL queries using prepared statements. The absence of dangerous functions, file operations, and external HTTP requests is also encouraging. However, the presence of two known CVEs in its history, including a past high-severity vulnerability, is a significant concern, suggesting a potential for recurring security weaknesses. While no CVEs are currently unpatched, the history of past vulnerabilities, particularly Cross-Site Scripting (XSS), indicates a need for ongoing vigilance and thorough code reviews by the developers. The limited attack surface with only two shortcodes, and zero unprotected entry points, is a positive aspect, but past vulnerabilities suggest that the sanitization or escaping logic might have been insufficient in previous versions.

In conclusion, while the current version of "cardoza-facebook-like-box" appears to have addressed immediate critical threats based on the static analysis, its historical vulnerability pattern, specifically the past high-severity XSS, warrants a cautious approach. Users should prioritize ensuring they are on the latest patched version and be aware that plugins with a history of vulnerabilities may require more frequent updates and monitoring. The developers have shown improvement in handling SQL and output escaping, but the past incident indicates a potential for subtle vulnerabilities to be introduced.

Key Concerns

  • Past high severity vulnerability
  • Past medium severity vulnerability
  • 82% output escaping is good, but 18% is not
Vulnerabilities
2 published

Easy Social Like Box – Popup – Sidebar Widget Security Vulnerabilities

CVEs by Year

1 CVE in 2014
2014
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2024-5224medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Easy Social Like Box – Popup – Sidebar Widget <= 4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Jun 5, 2024 Patched in 4.1 (33d)
CVE-2014-9524high · 7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Easy Social Like Box – Popup – Sidebar Widget < 2.8.3 - Cross-Site Scripting

Dec 12, 2014 Patched in 2.8.3 (3329d)
Version History

Easy Social Like Box – Popup – Sidebar Widget Release Timeline

v4.8Current
v4.7
v4.6
v4.5
v4.1
v3.01 CVE
v2.10.11 CVE
v2.91 CVE
v2.8.81 CVE
v2.8.71 CVE
v2.8.61 CVE
Code Analysis
Analyzed Mar 16, 2026

Easy Social Like Box – Popup – Sidebar Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
102 escaped
Nonce Checks
4
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

82% escaped124 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
cardoza_fb_like_options_page (cardoza_facebook_like_box.php:140)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Easy Social Like Box – Popup – Sidebar Widget Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[cardoza_facebook_like_box] cardoza_facebook_like_box.php:19
[cardoza_facebook_posts_like] cardoza_facebook_like_box.php:20
WordPress Hooks 12
actionadmin_initcardoza_facebook_like_box.php:13
actionadmin_enqueue_scriptscardoza_facebook_like_box.php:14
actionwp_enqueue_scriptscardoza_facebook_like_box.php:15
actionplugins_loadedcardoza_facebook_like_box.php:16
actionadmin_menucardoza_facebook_like_box.php:17
actionwp_footercardoza_facebook_like_box.php:18
actionadmin_enqueue_scriptscardoza_facebook_like_box.php:21
actionlogin_enqueue_scriptscardoza_facebook_like_box.php:22
filterthe_contentcardoza_facebook_like_box.php:922
actionwidgets_initcardoza_facebook_like_box.php:1188
actionadmin_enqueue_scriptscardoza_facebook_like_box.php:1196
actionlogin_enqueue_scriptscardoza_facebook_like_box.php:1197
Maintenance & Trust

Easy Social Like Box – Popup – Sidebar Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 14, 2025
PHP min version7.2
Downloads478K

Community Trust

Rating88/100
Number of ratings18
Active installs7K
Developer Profile

Easy Social Like Box – Popup – Sidebar Widget Developer Profile

johnnash1975

1 plugin · 7K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
1681 days
View full developer profile
Detection Fingerprints

How We Detect Easy Social Like Box – Popup – Sidebar Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cardoza-facebook-like-box/admin_cardozafacebook.css/wp-content/plugins/cardoza-facebook-like-box/admin_cardozafacebook.js/wp-content/plugins/cardoza-facebook-like-box/cardozafacebook.css/wp-content/plugins/cardoza-facebook-like-box/cardozafacebook.js/wp-content/plugins/cardoza-facebook-like-box/cardozafacebook_popup.css
Script Paths
/wp-content/plugins/cardoza-facebook-like-box/admin_cardozafacebook.js/wp-content/plugins/cardoza-facebook-like-box/cardozafacebook.js

HTML / DOM Fingerprints

CSS Classes
cardoza-facebook-like-box
Shortcode Output
[cardoza_facebook_like_box][cardoza_facebook_posts_like]
FAQ

Frequently Asked Questions about Easy Social Like Box – Popup – Sidebar Widget