Easy Social Box / Page Plugin Security & Risk Analysis

wordpress.org/plugins/easy-facebook-like-box

Easy Social box display facebook like box. it enable Facebook Page owners to attract and gain Likes from their own website.

5K active installs v4.1.4 PHP + WP 2.8.6+ Updated May 29, 2024
easy-facebook-like-boxfacebook-likefacebook-like-boxfacebook-like-buttonfacebook-like-for-wordpress
92
A · Safe
CVEs total1
Unpatched0
Last CVEJan 25, 2023
Safety Verdict

Is Easy Social Box / Page Plugin Safe to Use in 2026?

Generally Safe

Score 92/100

Easy Social Box / Page Plugin has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jan 25, 2023Updated 1yr ago
Risk Assessment

The plugin 'easy-facebook-like-box' v4.1.4 exhibits a generally strong security posture in its static analysis. The absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and the use of prepared statements for SQL are all positive indicators. However, a significant concern arises from the output escaping, with only 59% of outputs being properly escaped. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, especially given the historical vulnerability data which shows a past medium-severity XSS issue.

The vulnerability history reveals a single medium-severity CVE related to XSS, which was last recorded on January 25, 2023. The fact that this CVE is currently unpatched is a significant red flag, indicating that users of this plugin are potentially exposed to known security risks. While the static analysis did not directly identify any taint flows or specific unescaped outputs that *led* to this CVE, the general lack of robust output escaping and the historical XSS vulnerability strongly suggest that the risk of XSS is present and unmitigated.

In conclusion, while the plugin demonstrates good practices in many areas like SQL handling and avoiding dangerous functions, the high percentage of unescaped outputs and the presence of an unpatched medium-severity XSS vulnerability in its history create a notable security risk. The lack of explicit capability checks and nonce checks on the single shortcode entry point also warrants attention, although no specific vulnerabilities were identified in these areas during static analysis.

Key Concerns

  • Significant portion of outputs not properly escaped
  • Unpatched medium severity CVE in history
  • Vulnerability history indicates XSS risk
  • Lack of capability checks on entry points
  • Lack of nonce checks on entry points
Vulnerabilities
1 published

Easy Social Box / Page Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-4754medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Easy Social Box / Page Plugin <= 4.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Jan 25, 2023 Patched in 4.1.3 (363d)
Version History

Easy Social Box / Page Plugin Release Timeline

v4.1.4Current
v4.1.3
v4.1.21 CVE
v4.1.11 CVE
v4.11 CVE
v4.01 CVE
v3.01 CVE
v2.11 CVE
v2.01 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Easy Social Box / Page Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
38
55 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

59% escaped93 total outputs
Attack Surface

Easy Social Box / Page Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[easy-fb-like-box] facebook-like-box.php:300
WordPress Hooks 2
actionwidgets_initfacebook-like-box.php:263
actioninitfacebook-like-box.php:302
Maintenance & Trust

Easy Social Box / Page Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 29, 2024
PHP min version
Downloads144K

Community Trust

Rating78/100
Number of ratings12
Active installs5K
Developer Profile

Easy Social Box / Page Plugin Developer Profile

iamshehryar

1 plugin · 5K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
363 days
View full developer profile
Detection Fingerprints

How We Detect Easy Social Box / Page Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-facebook-like-box/js/widget.js/wp-content/plugins/easy-facebook-like-box/css/widget.css
Script Paths
/wp-content/plugins/easy-facebook-like-box/js/widget.js
Version Parameters
easy-facebook-like-box/css/widget.css?ver=easy-facebook-like-box/js/widget.js?ver=

HTML / DOM Fingerprints

CSS Classes
easy-facebook-like-box-wrap
HTML Comments
<!-- easy-facebook-like-box --><!-- Widget Title --><!-- Facebook page url --><!-- Tabs -->+9 more
Data Attributes
id="easy_facebook_like_box"name="easy_facebook_like_boxid="easy_facebook_like_box_name="easy_facebook_like_box_
Shortcode Output
[easy-facebook-like-box][easy-facebook-like-box title="[easy-facebook-like-box url="[easy-facebook-like-box tabs="
FAQ

Frequently Asked Questions about Easy Social Box / Page Plugin