
FireCask Like & Share Button Security & Risk Analysis
wordpress.org/plugins/facebook-like-send-buttonInsert the Facebook Like and/or Send button to any post, page or template with this simple plugin. Also lets you add them via shortcode anywhere in yo …
Is FireCask Like & Share Button Safe to Use in 2026?
Generally Safe
Score 91/100FireCask Like & Share Button has a strong security track record. Known vulnerabilities have been patched promptly.
The 'facebook-like-send-button' plugin v1.3 exhibits a mixed security posture. On the positive side, the static analysis reveals no detected dangerous functions, no SQL queries that are not prepared, no file operations, and no external HTTP requests. The limited attack surface, consisting of a single shortcode with no apparent unprotected entry points, is also a strength. However, there are significant concerns. The absence of nonce checks and capability checks, especially given the plugin's interaction with user input via a shortcode, creates a potential for various attacks if not handled carefully within the shortcode itself. Furthermore, 30% of output is not properly escaped, which is a substantial portion and strongly suggests a risk of Cross-Site Scripting (XSS) vulnerabilities. The vulnerability history further amplifies these concerns, with two past medium-severity CVEs, both related to XSS. The fact that the last vulnerability was in early 2025 and is now marked as 'currently unpatched' (this might be a typo in the provided data and likely means the CVEs exist but have patches available, or the plugin version is vulnerable) is worrying, especially as the common vulnerability type points to XSS. The lack of taint analysis data is also a gap that prevents a deeper understanding of potential data manipulation risks.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
- Past medium severity XSS vulnerabilities
FireCask Like & Share Button Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
FireCask Like & Share Button <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter
Peadig's Like & Share Button <= 1.1.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
FireCask Like & Share Button Code Analysis
Output Escaping
FireCask Like & Share Button Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
FireCask Like & Share Button Maintenance & Trust
Maintenance Signals
Community Trust
FireCask Like & Share Button Alternatives
Easy Social Box / Page Plugin
easy-facebook-like-box
Easy Social box display facebook like box. it enable Facebook Page owners to attract and gain Likes from their own website.
RA-Socialize Button
ra-socialize-button
RA-Socialize Button adds a Google+, twitter and facebook button to your blog post.
Yet Another Social Plugin
yet-another-social-plugin
Add social networking share buttons above or below each posts. Easy customization and positioning of the buttons in the Options page.
Easy Embed Page Widget
embed-page-facebook
This is widget of showing Facebook page embedded in your website.short code [embed_facebook]
Easy Social Like Box – Popup – Sidebar Widget
cardoza-facebook-like-box
WP Facebook Like Box Plugin enables you to display the facebook page likes in sidebar widget or popup. Display like button for the posts.
FireCask Like & Share Button Developer Profile
11 plugins · 4K total installs
How We Detect FireCask Like & Share Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
//connect.facebook.net/%options['language']%/sdk.js#xfbml=1&appId=%options['appID']%&version=v2.3HTML / DOM Fingerprints
fb-likefb-comments<!-- Like & Share Button: https://firecask.com/services/development/wordpress/ -->data-hrefdata-layoutdata-actiondata-show-facesdata-sharedata-num-posts+2 more<div class="fb-like" <div class="fb-comments" <fb:like