
Fan Page Widget by ThemeNcode Security & Risk Analysis
wordpress.org/plugins/facebook-fan-page-widgetAn widget that will display Facebook Fan page like box. Uses latest API of Facebook (v 16.0)
Is Fan Page Widget by ThemeNcode Safe to Use in 2026?
Generally Safe
Score 91/100Fan Page Widget by ThemeNcode has a strong security track record. Known vulnerabilities have been patched promptly.
The "facebook-fan-page-widget" plugin version 2.1 presents a mixed security posture. On the positive side, it boasts a very small attack surface with no apparent AJAX or REST API entry points that lack authentication. All SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are common vectors for vulnerabilities. The absence of bundled libraries is also a good sign. However, a significant concern is the low percentage (35%) of properly escaped output. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, especially since the plugin has a history of such issues.
The vulnerability history reveals one medium-severity CVE related to XSS, which was recently patched. While the fact that it's currently unpatched is a positive sign, the repeated pattern of XSS vulnerabilities in its past suggests that sanitization and output escaping might not be consistently implemented across all code paths. The lack of nonces and capability checks on its single shortcode entry point, coupled with the low output escaping rate, means that any unsanitized user input processed by this shortcode could potentially lead to XSS if not handled carefully within the widget's rendering process.
In conclusion, while the plugin demonstrates strengths in areas like avoiding risky functions and SQL injection, its output escaping practices are a clear weakness. The history of XSS vulnerabilities reinforces this concern. Users should be aware of the potential for XSS due to the insufficient output escaping, even though the known CVE is patched and the attack surface is minimal. Continuous monitoring and updates are crucial.
Key Concerns
- Insufficient output escaping (35% properly escaped)
- No nonce checks on shortcode entry point
- No capability checks on shortcode entry point
- History of medium severity XSS vulnerability
Fan Page Widget by ThemeNcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Fan Page Widget by ThemeNcode <= 2.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Fan Page Widget by ThemeNcode Code Analysis
Output Escaping
Fan Page Widget by ThemeNcode Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Fan Page Widget by ThemeNcode Maintenance & Trust
Maintenance Signals
Community Trust
Fan Page Widget by ThemeNcode Alternatives
Mongoose Page Plugin
facebook-page-feed-graph-api
The most popular way to display the Facebook Page Plugin on your WordPress website. Easy implementation using a shortcode or widget.
Easy Social Like Box – Popup – Sidebar Widget
cardoza-facebook-like-box
WP Facebook Like Box Plugin enables you to display the facebook page likes in sidebar widget or popup. Display like button for the posts.
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Social Like Box and Page by WpDevArt
like-box
WordPress Facebook Like box plugin will help you to display like box on your website, just add our plugin widget to your sidebar and use it.
Easy Social Box / Page Plugin
easy-facebook-like-box
Easy Social box display facebook like box. it enable Facebook Page owners to attract and gain Likes from their own website.
Fan Page Widget by ThemeNcode Developer Profile
1 plugin · 1K total installs
How We Detect Fan Page Widget by ThemeNcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
fb-pagefb-xfbml-parse-ignoredata-hrefdata-widthdata-hide-coverdata-show-facepiledata-tabsdata-hide-cta+3 moreFB<div class="fb-page"