Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds Security & Risk Analysis

wordpress.org/plugins/facebook-pagelike-widget

Floating Social Media Icons, Sticky Share Buttons, Facebook Feeds, & Popup builder. Also, create Call, Email, SMS, & Contact buttons to increa …

50K active installs v7.0.0 PHP 7.0+ WP 4.7+ Updated Mar 9, 2026
facebook-feedsshareshare-buttonssocialsocial-media
99
A · Safe
CVEs total2
Unpatched0
Last CVEMar 25, 2025
Safety Verdict

Is Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds Safe to Use in 2026?

Generally Safe

Score 99/100

Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Mar 25, 2025Updated 25d ago
Risk Assessment

The facebook-pagelike-widget plugin v7.0.0 presents a mixed security posture. While it demonstrates good practices by using prepared statements for all SQL queries and having a reasonable number of nonce and capability checks, significant concerns arise from its attack surface and output escaping. The plugin exposes 8 entry points, with a concerning 6 of these being unprotected, primarily due to the lack of permission callbacks on all 6 REST API routes. This large unprotected attack surface increases the risk of unauthorized actions or information disclosure. Additionally, only 52% of output is properly escaped, leaving a substantial portion vulnerable to cross-site scripting (XSS) attacks, which aligns with its historical vulnerability types. The plugin has a history of 2 medium severity CVEs, both related to XSS, indicating a recurring weakness that, while currently patched, suggests a need for diligent code review and secure coding practices. The taint analysis did not reveal critical or high severity issues, which is a positive sign, but the presence of unsanitized paths warrants attention. Overall, the plugin has strengths in database interaction but weaknesses in access control for its API endpoints and output sanitization, creating a moderate to high risk profile.

Key Concerns

  • Unprotected REST API routes
  • Low percentage of properly escaped output
  • Unsanitized paths in taint analysis
  • Historical medium severity CVEs (XSS)
Vulnerabilities
2

Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-13207medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Widget for Social Page Feeds <= 6.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

Mar 25, 2025 Patched in 6.4.2 (28d)
CVE-2024-0973medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Widget for Social Page Feeds <= 6.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

Feb 21, 2024 Patched in 6.4 (23d)
Code Analysis
Analyzed Mar 16, 2026

Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
65
71 escaped
Nonce Checks
7
Capability Checks
4
File Operations
4
External Requests
1
Bundled Libraries
0

Output Escaping

52% escaped136 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
bzsf_redirect_to_page (init.php:48)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds Attack Surface

Entry Points8
Unprotected6

REST API Routes 6

GET/wp-json/bz_social_feeds/analytics/overviewapp\Api\Analytics\Overview.php:32
GET/wp-json/bz_social_feeds/connectapp\Api\Connection\Connect.php:35
GET/wp-json/bz_social_feeds/disconnectapp\Api\Connection\Disconnect.php:38
GET/wp-json/bz_social_feeds/editor_start_sessionapp\Api\Connection\StartEditorSession.php:33
GET/wp-json/bz_social_feeds/syncapp\Api\Connection\Sync.php:34
GET/wp-json/bz_social_feeds/settingsapp\Api\Settings\UpdateSettings.php:33

Shortcodes 2

[fb_widget] app\SocialFeeds\Shortcode.php:56
[buttonizer] init.php:181
WordPress Hooks 18
actionadmin_menuapp\Admin\Admin.php:36
actionadmin_initapp\Admin\Admin.php:39
actionadmin_enqueue_scriptsapp\Admin\Admin.php:42
filterscript_loader_tagapp\Admin\Admin.php:45
actionadmin_noticesapp\Admin\Admin.php:59
actionadmin_enqueue_scriptsapp\SocialFeeds\Widget.php:15
actionadmin_enqueue_scriptsapp\SocialFeeds\Widget.php:16
actionwidgets_initapp\SocialFeeds\Widget.php:222
actionwp_enqueue_scriptsfacebook_widget.php:63
actionplugins_loadedfacebook_widget.php:68
actioninitfacebook_widget.php:100
actionenqueue_block_assetsfacebook_widget.php:102
actiontemplate_redirectinit.php:97
actionwp_headinit.php:103
actionwp_footerinit.php:135
actioninitinit.php:185
actionadmin_bar_menuinit.php:188
actionrest_api_initinit.php:195
Maintenance & Trust

Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version7.0
Downloads1.7M

Community Trust

Rating96/100
Number of ratings394
Active installs50K
Developer Profile

Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds Developer Profile

Buttonizer

3 plugins · 190K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
155 days
View full developer profile
Detection Fingerprints

How We Detect Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/facebook-pagelike-widget/assets/css/style.css
Script Paths
https://connect.facebook.net/%s/sdk.js
Version Parameters
facebook-pagelike-widget/assets/css/style.css?ver=bzsf-block-editor-script

HTML / DOM Fingerprints

Data Attributes
data-bz_social_feeds
JS Globals
fbWidgetData
FAQ

Frequently Asked Questions about Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds