BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress Security & Risk Analysis

wordpress.org/plugins/facebook-button-plugin

Add Facebook Follow, Like, and Share buttons to WordPress posts, pages, and widgets.

5K active installs v2.77 PHP + WP 5.6+ Updated Jun 12, 2025
add-share-buttonfacebook-buttonslikesharesocial-buttons
99
A · Safe
CVEs total2
Unpatched0
Last CVENov 29, 2023
Safety Verdict

Is BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress Safe to Use in 2026?

Generally Safe

Score 99/100

BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Nov 29, 2023Updated 9mo ago
Risk Assessment

The 'facebook-button-plugin' version 2.77 exhibits a generally good security posture with a substantial number of code signals indicating robust security practices. The plugin demonstrates strong adherence to output escaping (96%), a high number of nonce checks, and capability checks, which are crucial for protecting against common web vulnerabilities. Furthermore, the taint analysis reveals no critical or high-severity unsanitized flows, and the static analysis shows no unprotected entry points, which are positive indicators.

However, the plugin's vulnerability history is a significant concern. With two known medium-severity CVEs, including 'Exposure of Sensitive Information to an Unauthorized Actor' and 'Cross-site Scripting,' and the most recent one occurring in late 2023, it suggests a recurring pattern of exploitable weaknesses. While currently unpatched CVEs are zero, the historical presence of these vulnerability types warrants caution, as similar issues could emerge in future versions if code quality is not consistently maintained. The static analysis also indicates that 50% of SQL queries are not using prepared statements, which presents a potential risk for SQL injection vulnerabilities, though the taint analysis did not detect any active exploitation pathways for this version.

In conclusion, while version 2.77 has implemented many good security practices and currently appears free of critical vulnerabilities, the plugin's past vulnerability record necessitates vigilance. The use of raw SQL queries and the historical presence of XSS and information exposure vulnerabilities are weaknesses that should be addressed to improve the overall security posture and prevent recurrence.

Key Concerns

  • Half of SQL queries use prepared statements
  • Two medium severity CVEs in vulnerability history
  • Recent vulnerability in late 2023
Vulnerabilities
2

BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2017
2017
1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2023-6250medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

BestWebSoft's Like & Share <= 2.73 - Unauthenticated Password Protected Post Disclosure

Nov 29, 2023 Patched in 2.74 (70d)
WF-305f9e72-3a3f-4b22-8097-f37b1a1ebe1d-facebook-button-pluginmedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress < 2.5.4 - Reflected Cross-Site Scripting

Apr 12, 2017 Patched in 2.5.4 (2477d)
Code Analysis
Analyzed Mar 16, 2026

BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
2 prepared
Unescaped Output
19
509 escaped
Nonce Checks
21
Capability Checks
3
File Operations
4
External Requests
6
Bundled Libraries
0

SQL Query Safety

50% prepared4 total queries

Output Escaping

96% escaped528 total outputs
Data Flows
All sanitized

Data Flow Analysis

6 flows
bws_add_menu_render (bws_menu\bws_menu.php:18)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_bws_submit_request_feature_actionbws_menu\class-bws-settings.php:1466
authwp_ajax_bws_submit_uninstall_reason_actionbws_menu\deactivation-form.php:433

Shortcodes 1

[fb_button] facebook-button-plugin.php:1207
WordPress Hooks 25
filterload_textdomain_mofilebws_menu\bws_functions.php:43
filtermce_external_pluginsbws_menu\bws_functions.php:1296
filtermce_buttonsbws_menu\bws_functions.php:1297
actionadmin_initbws_menu\bws_functions.php:1584
actionadmin_enqueue_scriptsbws_menu\bws_functions.php:1585
actionadmin_headbws_menu\bws_functions.php:1586
actionadmin_footerbws_menu\bws_functions.php:1587
actionadmin_noticesbws_menu\bws_functions.php:1589
actionwp_enqueue_scriptsbws_menu\bws_functions.php:1591
filterthe_contentfacebook-button-plugin.php:221
filterthe_excerptfacebook-button-plugin.php:223
actionadmin_menufacebook-button-plugin.php:1193
actionplugins_loadedfacebook-button-plugin.php:1195
actioninitfacebook-button-plugin.php:1196
actionadmin_initfacebook-button-plugin.php:1197
actionloop_startfacebook-button-plugin.php:1198
actionwp_enqueue_scriptsfacebook-button-plugin.php:1200
actionadmin_enqueue_scriptsfacebook-button-plugin.php:1201
actionwp_headfacebook-button-plugin.php:1203
actionwp_footerfacebook-button-plugin.php:1204
filterpgntn_callbackfacebook-button-plugin.php:1205
filterbws_shortcode_button_contentfacebook-button-plugin.php:1209
filterplugin_action_linksfacebook-button-plugin.php:1211
filterplugin_row_metafacebook-button-plugin.php:1212
actionadmin_noticesfacebook-button-plugin.php:1214
Maintenance & Trust

BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 12, 2025
PHP min version
Downloads1.3M

Community Trust

Rating78/100
Number of ratings72
Active installs5K
Developer Profile

BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress Developer Profile

bestweblayout

32 plugins · 17K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
1944 days
View full developer profile
Detection Fingerprints

How We Detect BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
facebook-button-plugin/style.css?ver=facebook-button-plugin/js/frontend.min.js?ver=facebook-button-plugin/js/backend.min.js?ver=facebook-button-plugin/css/frontend.min.css?ver=facebook-button-plugin/css/backend.min.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress