
Engaging Buttons Security & Risk Analysis
wordpress.org/plugins/engaging-buttonsEasily add research-based, engaging buttons (such as "Respect" or "Important") to your site.
Is Engaging Buttons Safe to Use in 2026?
Generally Safe
Score 85/100Engaging Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'engaging-buttons' plugin v1.0.6 exhibits a mixed security posture. While the absence of recorded vulnerabilities and a lack of dangerous functions or file operations are positive indicators, significant concerns arise from the static analysis. A substantial portion of the plugin's attack surface, specifically 4 out of 5 identified entry points (AJAX handlers), lack authentication checks. This presents a high risk of unauthorized access and potential manipulation of plugin functionalities.
Furthermore, the low percentage of properly escaped output (15%) indicates a strong likelihood of cross-site scripting (XSS) vulnerabilities. Combined with the unprotected AJAX handlers, an attacker could potentially inject malicious scripts through these entry points, leading to compromised user sessions or data theft. The presence of raw SQL queries without prepared statements also introduces a risk of SQL injection, although the overall number is moderate.
The plugin's vulnerability history is currently clean, which is a positive sign and suggests that the developers may be diligent. However, this must be weighed against the immediate risks identified in the static analysis. The lack of taint analysis data is a limitation, but the existing code signals are sufficient to warrant caution. In conclusion, while the plugin has a clean track record, the identified lack of authentication on AJAX handlers and poor output escaping practices create significant security weaknesses that require immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Low output escaping percentage
- SQL queries without prepared statements
- Limited nonce checks
Engaging Buttons Security Vulnerabilities
Engaging Buttons Release Timeline
Engaging Buttons Code Analysis
SQL Query Safety
Output Escaping
Engaging Buttons Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 31
Scheduled Events 1
Maintenance & Trust
Engaging Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Engaging Buttons Alternatives
WP ULike – Like & Dislike Buttons for Engagement and Feedback
wp-ulike
Voting buttons that let your visitors give instant feedback. See what your audience loves with no registration, no friction, just one click.
WP Shortcode by MyThemeShop
wp-shortcode
WP Shortcode is a premium WP plugin for free, that provides easy to use over 24 shortcodes. You can easily add buttons, alerts, videos and more.
Bootstrap Shortcodes
bootstrap-shortcodes
Wordpress plugin to add shortcodes for Twitter Bootstrap 3.3
BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress
facebook-button-plugin
Add Facebook Follow, Like, and Share buttons to WordPress posts, pages, and widgets.
Arconix Shortcodes
arconix-shortcodes
Arconix Shortcodes provides a number of useful design elements like buttons, boxes, tabs and toggles to help compliment any website.
Engaging Buttons Developer Profile
1 plugin · 10 total installs
How We Detect Engaging Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/engaging-buttons/admin/css/enp-admin-styles.css/wp-content/plugins/engaging-buttons/front-end/css/enp-button-admin-button-styles.min.css/wp-content/plugins/engaging-buttons/admin/js/enp-admin-scripts.js/wp-content/plugins/engaging-buttons/admin/js/enp-admin-scripts.jsengaging-buttons/admin/css/enp-admin-styles.css?ver=engaging-buttons/front-end/css/enp-button-admin-button-styles.min.css?ver=engaging-buttons/admin/js/enp-admin-scripts.js?ver=HTML / DOM Fingerprints
enp-btn--user-has-not-clickedenp-btn--user-clickeddata-enp-button-idenp_admin_button_script_vars