
Da Reactions Security & Risk Analysis
wordpress.org/plugins/da-reactionsThis plugin creates some reaction buttons that could be added to content and comments.
Is Da Reactions Safe to Use in 2026?
Generally Safe
Score 99/100Da Reactions has a strong security track record. Known vulnerabilities have been patched promptly.
The 'da-reactions' v5.3.4 plugin exhibits a generally good security posture, with strengths in its use of prepared statements for SQL queries and a high percentage of properly escaped output. The absence of unauthenticated AJAX handlers and REST API routes, coupled with the presence of nonce and capability checks, indicates an effort to secure its entry points. However, the presence of two taint flows with unsanitized paths, even without a critical or high severity rating, warrants attention as it suggests potential for input manipulation. The plugin's vulnerability history shows one medium severity CVE related to Cross-site Scripting, which was patched. While the lack of currently unpatched vulnerabilities is positive, the past occurrence of XSS highlights the importance of continued vigilance in output sanitization and input validation, particularly concerning the identified unsanitized paths.
Key Concerns
- Taint flows with unsanitized paths
- Past medium severity XSS vulnerability
Da Reactions Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Da Reactions <= 5.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Da Reactions Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Da Reactions Attack Surface
Shortcodes 1
Maintenance & Trust
Da Reactions Maintenance & Trust
Maintenance Signals
Community Trust
Da Reactions Alternatives
Booster Extension
booster-extension
Booster Extension is a free WordPress plugin that supercharges your site with awesome powerful features. There’re numerous plugins in the official Wor …
React & Share – Customizable Reaction Buttons
react-and-share
Get feedback and see what your readers think about your articles.
WPAC Social Tools – Like, React & Share
wpac-like-system
The Most Simple WordPress Post Like, Dislike & Reaction System with Social Sharing.
Awesome Emoji Reactions
awesome-emoji-reactions
Add emoji reactions to your WordPress posts to increase user engagement and get instant feedback from your audience.
Emojis for Posts and Pages
emojis-for-posts-and-pages
Add colorful emoji reactions to your WordPress posts and pages, similar to Facebook reactions.
Da Reactions Developer Profile
3 plugins · 1K total installs
How We Detect Da Reactions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/da-reactions/assets/css/admin.css/wp-content/plugins/da-reactions/assets/css/da-reactions.css/wp-content/plugins/da-reactions/assets/css/da-reactions.theme.css/wp-content/plugins/da-reactions/assets/js/admin/buttons.js/wp-content/plugins/da-reactions/assets/js/admin/general.js/wp-content/plugins/da-reactions/assets/js/admin/graphic.js/wp-content/plugins/da-reactions/assets/js/admin/import-votes.js/wp-content/plugins/da-reactions/assets/js/admin/votes-list.js+3 more/wp-content/plugins/da-reactions/assets/js/da-reactions.frontend.jsda-reactions/assets/css/admin.css?ver=da-reactions/assets/css/da-reactions.css?ver=da-reactions/assets/css/da-reactions.theme.css?ver=da-reactions/assets/js/admin/buttons.js?ver=da-reactions/assets/js/admin/general.js?ver=da-reactions/assets/js/admin/graphic.js?ver=da-reactions/assets/js/admin/import-votes.js?ver=da-reactions/assets/js/admin/votes-list.js?ver=da-reactions/assets/js/da-reactions.js?ver=da-reactions/assets/js/da-reactions.admin.js?ver=da-reactions/assets/js/da-reactions.frontend.js?ver=HTML / DOM Fingerprints
da-reactions-react-buttonda-reactions-react-button-wrapda-reactions-react-button-votersda-reactions-react-button-voters-list<!-- START DA_REACTIONS --><!-- END DA_REACTIONS --><!-- START FREEMIUS --><!-- END FREEMIUS -->+1 moredata-da-reactions-post-iddata-da-reactions-comment-iddata-da-reactions-nonceda_reactions_params/wp-json/da-reactions/v1/react[da_reactions][da_reactions_frontend]