
I Recommend This – Love/Like Button for WordPress Posts Security & Risk Analysis
wordpress.org/plugins/i-recommend-thisEnable your visitors to easily like or recommend your posts with a single click, enhancing engagement without the need for comments.
Is I Recommend This – Love/Like Button for WordPress Posts Safe to Use in 2026?
Generally Safe
Score 96/100I Recommend This – Love/Like Button for WordPress Posts has a strong security track record. Known vulnerabilities have been patched promptly.
The i-recommend-this plugin v4.0.1 demonstrates some good security practices, notably the complete absence of raw SQL queries and a high percentage of properly escaped output. The plugin also employs nonce and capability checks on some entry points. However, the analysis reveals significant concerns. The presence of unsanitized paths in taint analysis is particularly worrying, with three identified flows flagged as high severity. This indicates potential pathways for attackers to inject malicious code or data. Furthermore, the plugin has a history of 5 known CVEs, including one critical, two high, and two medium severity vulnerabilities. While none are currently unpatched, this pattern of past vulnerabilities, especially critical and high severity ones related to XSS, CSRF, and SQL Injection, suggests a recurring tendency for security flaws to be introduced. The lack of explicit permission callbacks on all REST API routes (though none exist currently) and the fact that not all AJAX handlers have authentication checks also represent potential future attack vectors if new endpoints are added without proper security considerations.
Key Concerns
- High severity unsanitized taint flows (3)
- Past critical severity CVEs (1)
- Past high severity CVEs (2)
- Past medium severity CVEs (2)
- AJAX handlers without auth checks (implied 0 out of 2)
- Potential for future unpatched REST API vulnerabilities
I Recommend This – Love/Like Button for WordPress Posts Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
I Recommend This <= 3.8.3 - Authenticated (Admin+) Stored Cross-Site Scripting
I Recommend This <= 3.9.0 - Cross-Site Request Forgery
I Recommend This < 3.8.2 - Cross-Site Scripting
I Recommend This < 3.7.3 - SQL Injection
I Recommend This <= 3.7.2 - Authenticated (Subscriber+) SQL Injection via Shortcode
I Recommend This – Love/Like Button for WordPress Posts Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
I Recommend This – Love/Like Button for WordPress Posts Attack Surface
AJAX Handlers 2
Shortcodes 4
WordPress Hooks 24
Maintenance & Trust
I Recommend This – Love/Like Button for WordPress Posts Maintenance & Trust
Maintenance Signals
Community Trust
I Recommend This – Love/Like Button for WordPress Posts Alternatives
BuddyPress Like
buddypress-like
Gives users the ability to 'like' content across your BuddyPress enabled site.
Post Reaction – Add Like or Emoji Reactions to Posts
post-reaction
Add Facebook Reaction interface in WordPress Posts and Count them (likes, loves, cares, custom react)
Zaki Like Dislike Comments
zaki-like-dislike-comments
This plugin implements a "like/dislike" rating system for comments
Love It
love-it
Love It is a simple plugin that adds a "Love It" link to your posts, pages, and custom post types. Show your most popular items in a widget.
Managed posts rating ★ Like button
managed-posts-rating-like-button
Rating system for your WordPress site with a simple "like" button and advanced admin panel.
I Recommend This – Love/Like Button for WordPress Posts Developer Profile
7 plugins · 13K total installs
How We Detect I Recommend This – Love/Like Button for WordPress Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/i-recommend-this/assets/css/admin-settings.css/wp-content/plugins/i-recommend-this/assets/js/admin-tabs.jsi-recommend-this/assets/css/admin-settings.css?ver=i-recommend-this/assets/js/admin-tabs.js?ver=HTML / DOM Fingerprints
irecommendthis-settingsirecommendthis-settings-formnav-tab-activenotice-successcarddata-tab[recommend_this][irecommend_this_counter][irecommend_this_list]