
BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/facebook-button-pluginAdd Facebook Follow, Like, and Share buttons to WordPress posts, pages, and widgets.
Is BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 99/100BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The 'facebook-button-plugin' version 2.77 exhibits a generally good security posture with a substantial number of code signals indicating robust security practices. The plugin demonstrates strong adherence to output escaping (96%), a high number of nonce checks, and capability checks, which are crucial for protecting against common web vulnerabilities. Furthermore, the taint analysis reveals no critical or high-severity unsanitized flows, and the static analysis shows no unprotected entry points, which are positive indicators.
However, the plugin's vulnerability history is a significant concern. With two known medium-severity CVEs, including 'Exposure of Sensitive Information to an Unauthorized Actor' and 'Cross-site Scripting,' and the most recent one occurring in late 2023, it suggests a recurring pattern of exploitable weaknesses. While currently unpatched CVEs are zero, the historical presence of these vulnerability types warrants caution, as similar issues could emerge in future versions if code quality is not consistently maintained. The static analysis also indicates that 50% of SQL queries are not using prepared statements, which presents a potential risk for SQL injection vulnerabilities, though the taint analysis did not detect any active exploitation pathways for this version.
In conclusion, while version 2.77 has implemented many good security practices and currently appears free of critical vulnerabilities, the plugin's past vulnerability record necessitates vigilance. The use of raw SQL queries and the historical presence of XSS and information exposure vulnerabilities are weaknesses that should be addressed to improve the overall security posture and prevent recurrence.
Key Concerns
- Half of SQL queries use prepared statements
- Two medium severity CVEs in vulnerability history
- Recent vulnerability in late 2023
BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
BestWebSoft's Like & Share <= 2.73 - Unauthenticated Password Protected Post Disclosure
BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress < 2.5.4 - Reflected Cross-Site Scripting
BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 25
Maintenance & Trust
BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress Alternatives
Share It for All Users on BuddyPress YR
buddy-share-it-allusers-fb-yr
For generate WP custom buttons, social share, Facebook Like, Buddypress Activity buttons, Viber Whatsapp Telegram Google and other buttons
Simple Share Buttons Adder
simple-share-buttons-adder
A simple plugin that enables you to add share buttons to all of your posts and/or pages.
Hubbub Lite – Fast, free social sharing and follow buttons
social-pug
Your content is worth sharing. Let's makes it easier!
ShareThis Share Buttons
sharethis-share-buttons
Grow your website traffic and engagement by enabling one-click sharing with the free ShareThis Share Buttons plugin. The plugin is free (no upgrades a …
Simple Social Media Share Buttons – Social Sharing for Everyone
simple-social-buttons
This Social Share Plugin adds advanced social media sharing buttons to your WordPress sites, such as Facebook, WhatsApp, X, LinkedIn, & Pinterest.
BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress Developer Profile
32 plugins · 17K total installs
How We Detect BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
facebook-button-plugin/style.css?ver=facebook-button-plugin/js/frontend.min.js?ver=facebook-button-plugin/js/backend.min.js?ver=facebook-button-plugin/css/frontend.min.css?ver=facebook-button-plugin/css/backend.min.css?ver=