
Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds Security & Risk Analysis
wordpress.org/plugins/facebook-pagelike-widgetFloating Social Media Icons, Sticky Share Buttons, Facebook Feeds, & Popup builder. Also, create Call, Email, SMS, & Contact buttons to increa …
Is Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds Safe to Use in 2026?
Generally Safe
Score 99/100Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds has a strong security track record. Known vulnerabilities have been patched promptly.
The facebook-pagelike-widget plugin v7.0.0 presents a mixed security posture. While it demonstrates good practices by using prepared statements for all SQL queries and having a reasonable number of nonce and capability checks, significant concerns arise from its attack surface and output escaping. The plugin exposes 8 entry points, with a concerning 6 of these being unprotected, primarily due to the lack of permission callbacks on all 6 REST API routes. This large unprotected attack surface increases the risk of unauthorized actions or information disclosure. Additionally, only 52% of output is properly escaped, leaving a substantial portion vulnerable to cross-site scripting (XSS) attacks, which aligns with its historical vulnerability types. The plugin has a history of 2 medium severity CVEs, both related to XSS, indicating a recurring weakness that, while currently patched, suggests a need for diligent code review and secure coding practices. The taint analysis did not reveal critical or high severity issues, which is a positive sign, but the presence of unsanitized paths warrants attention. Overall, the plugin has strengths in database interaction but weaknesses in access control for its API endpoints and output sanitization, creating a moderate to high risk profile.
Key Concerns
- Unprotected REST API routes
- Low percentage of properly escaped output
- Unsanitized paths in taint analysis
- Historical medium severity CVEs (XSS)
Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Widget for Social Page Feeds <= 6.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Widget for Social Page Feeds <= 6.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds Code Analysis
Output Escaping
Data Flow Analysis
Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds Attack Surface
REST API Routes 6
Shortcodes 2
WordPress Hooks 18
Maintenance & Trust
Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds Maintenance & Trust
Maintenance Signals
Community Trust
Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds Alternatives
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Simple Social Media Share Buttons – Social Sharing for Everyone
simple-social-buttons
This Social Share Plugin adds advanced social media sharing buttons to your WordPress sites, such as Facebook, WhatsApp, X, LinkedIn, & Pinterest.
Social Sharing Plugin – Social Warfare
social-warfare
The most beautiful, responsive, lightning fast social share buttons built to boost shares and drive more traffic without slowing down your site.
Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds Developer Profile
3 plugins · 190K total installs
How We Detect Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/facebook-pagelike-widget/assets/css/style.csshttps://connect.facebook.net/%s/sdk.jsfacebook-pagelike-widget/assets/css/style.css?ver=bzsf-block-editor-scriptHTML / DOM Fingerprints
data-bz_social_feedsfbWidgetData