FireCask Like & Share Button Security & Risk Analysis

wordpress.org/plugins/facebook-like-send-button

Insert the Facebook Like and/or Send button to any post, page or template with this simple plugin. Also lets you add them via shortcode anywhere in yo …

400 active installs v1.3 PHP + WP 5.2+ Updated Jan 20, 2025
facebookfacebook-likefacebook-like-buttonlikelike-button
91
A · Safe
CVEs total2
Unpatched0
Last CVEJan 20, 2025
Safety Verdict

Is FireCask Like & Share Button Safe to Use in 2026?

Generally Safe

Score 91/100

FireCask Like & Share Button has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jan 20, 2025Updated 1yr ago
Risk Assessment

The 'facebook-like-send-button' plugin v1.3 exhibits a mixed security posture. On the positive side, the static analysis reveals no detected dangerous functions, no SQL queries that are not prepared, no file operations, and no external HTTP requests. The limited attack surface, consisting of a single shortcode with no apparent unprotected entry points, is also a strength. However, there are significant concerns. The absence of nonce checks and capability checks, especially given the plugin's interaction with user input via a shortcode, creates a potential for various attacks if not handled carefully within the shortcode itself. Furthermore, 30% of output is not properly escaped, which is a substantial portion and strongly suggests a risk of Cross-Site Scripting (XSS) vulnerabilities. The vulnerability history further amplifies these concerns, with two past medium-severity CVEs, both related to XSS. The fact that the last vulnerability was in early 2025 and is now marked as 'currently unpatched' (this might be a typo in the provided data and likely means the CVEs exist but have patches available, or the plugin version is vulnerable) is worrying, especially as the common vulnerability type points to XSS. The lack of taint analysis data is also a gap that prevents a deeper understanding of potential data manipulation risks.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
  • Past medium severity XSS vulnerabilities
Vulnerabilities
2

FireCask Like & Share Button Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-11226medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

FireCask Like & Share Button <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter

Jan 20, 2025 Patched in 1.3 (1d)
CVE-2023-25783medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Peadig's Like & Share Button <= 1.1.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

Feb 15, 2023 Patched in 1.2 (342d)
Code Analysis
Analyzed Mar 16, 2026

FireCask Like & Share Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
23 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

70% escaped33 total outputs
Attack Surface

FireCask Like & Share Button Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[fbls] class-frontend.php:159
WordPress Hooks 7
actionadmin_initclass-admin.php:9
actionadmin_menuclass-admin.php:34
filterlanguage_attributesclass-frontend.php:4
actionwp_headclass-frontend.php:31
actionwp_footerclass-frontend.php:56
filterthe_contentclass-frontend.php:102
filterwidget_textclass-frontend.php:158
Maintenance & Trust

FireCask Like & Share Button Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 20, 2025
PHP min version
Downloads48K

Community Trust

Rating54/100
Number of ratings7
Active installs400
Developer Profile

FireCask Like & Share Button Developer Profile

Alex Moss

11 plugins · 4K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
249 days
View full developer profile
Detection Fingerprints

How We Detect FireCask Like & Share Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
//connect.facebook.net/%options['language']%/sdk.js#xfbml=1&appId=%options['appID']%&version=v2.3

HTML / DOM Fingerprints

CSS Classes
fb-likefb-comments
HTML Comments
<!-- Like & Share Button: https://firecask.com/services/development/wordpress/ -->
Data Attributes
data-hrefdata-layoutdata-actiondata-show-facesdata-sharedata-num-posts+2 more
Shortcode Output
<div class="fb-like" <div class="fb-comments" <fb:like
FAQ

Frequently Asked Questions about FireCask Like & Share Button