
Profile Box Shortcode And Widget Security & Risk Analysis
wordpress.org/plugins/facebook-likebox-widget-and-shortcodeA very easy and simple Facebook like box shortcode and widget plugin with mini profile, like Button, Share Button plugin For WordPress
Is Profile Box Shortcode And Widget Safe to Use in 2026?
Generally Safe
Score 100/100Profile Box Shortcode And Widget has a strong security track record. Known vulnerabilities have been patched promptly.
The "facebook-likebox-widget-and-shortcode" plugin v1.2.3 exhibits a generally good security posture with several positive indicators. The absence of AJAX handlers and REST API routes without authentication checks, coupled with the use of prepared statements for all SQL queries, significantly reduces common attack vectors. The presence of nonce and capability checks, along with a complete lack of file operations and external HTTP requests, further strengthens its defenses. However, a concerning aspect is the moderate output escaping rate (63%), which suggests potential for Cross-Site Scripting (XSS) vulnerabilities if the unescaped outputs are triggered by user-supplied data. The vulnerability history, showing one medium-severity XSS vulnerability patched in February 2024, reinforces this concern. While currently patched, it indicates a past weakness in input sanitization or output encoding that could re-emerge if not thoroughly addressed. The plugin's attack surface is minimal, primarily consisting of a single shortcode, which is a positive sign. The lack of critical or high-severity taint flows is also reassuring.
In conclusion, the plugin demonstrates strengths in its limited attack surface and secure handling of database operations and external interactions. The primary area for improvement and continued vigilance lies in ensuring all output is properly escaped to mitigate the risk of XSS, as evidenced by past vulnerabilities. The plugin's current state is relatively secure, but the moderate output escaping rate and past XSS vulnerability warrant attention to maintain this security.
Key Concerns
- Moderate output escaping rate
- Past medium severity XSS vulnerability
Profile Box Shortcode And Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Profile Box Shortcode And Widget <= 1.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Profile Box Shortcode And Widget Code Analysis
Output Escaping
Profile Box Shortcode And Widget Attack Surface
Shortcodes 1
WordPress Hooks 36
Maintenance & Trust
Profile Box Shortcode And Widget Maintenance & Trust
Maintenance Signals
Community Trust
Profile Box Shortcode And Widget Alternatives
Easy Social Like Box – Popup – Sidebar Widget
cardoza-facebook-like-box
WP Facebook Like Box Plugin enables you to display the facebook page likes in sidebar widget or popup. Display like button for the posts.
Easy Social Box / Page Plugin
easy-facebook-like-box
Easy Social box display facebook like box. it enable Facebook Page owners to attract and gain Likes from their own website.
All-in-one Like Widget
all-in-one-facebook-like-widget
All-in-one Like Widget. Lets you quickly add a Like Button, activity stream and/or a Fanbox to your WordPress site for your Facebook fanpage (as a wid …
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
Profile Box Shortcode And Widget Developer Profile
61 plugins · 64K total installs
How We Detect Profile Box Shortcode And Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/facebook-likebox-widget-and-shortcode/css/style.css/wp-content/plugins/facebook-likebox-widget-and-shortcode/js/script.jsfacebook-likebox-widget-and-shortcode/css/style.css?ver=facebook-likebox-widget-and-shortcode/js/script.js?ver=HTML / DOM Fingerprints
fb-pagefb-xfbml-parse-ignoreawplife-credit-linkdata-hrefdata-widthdata-heightdata-small-headerdata-adapt-container-widthdata-hide-cover+2 morewindow.fbAsyncInitFB.initFB.Canvas.setAutoResize<div class="fb-page"window.fbAsyncInit = function() {FB.init({appId :