Like to Unlock lite Security & Risk Analysis

wordpress.org/plugins/jcwp-like-to-unlock-lite

This plugin gives you control to initially hide part of your article from user. Content is displayed correctly once user Facebook Like or +1 your page

10 active installs v1.1 PHP + WP 3.3.0+ Updated Apr 16, 2015
facebook-likegoogle-1google-plus-onehide-contenthide-part-of-post
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Like to Unlock lite Safe to Use in 2026?

Generally Safe

Score 85/100

Like to Unlock lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "jcwp-like-to-unlock-lite" v1.1 plugin exhibits a mixed security posture. On one hand, the lack of identified CVEs and a clean vulnerability history are positive indicators, suggesting a generally secure development approach and diligent maintenance. The absence of dangerous functions, file operations, external requests, and the use of prepared statements for all SQL queries are strong security practices.

However, significant concerns arise from the static analysis. The most critical weakness is that 100% of the identified output operations are not properly escaped. This presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the context of the user's browser. Furthermore, the complete absence of nonce and capability checks, even with zero identified entry points, is a notable oversight. While there are no current entry points, if any were to be introduced in future updates, they would likely be unprotected, leaving the plugin vulnerable to unauthorized actions or privilege escalation.

In conclusion, while the plugin benefits from a lack of historical vulnerabilities and good practices in data handling, the critical flaw of unescaped output and the complete absence of access control mechanisms are serious security concerns that significantly outweigh the positive aspects. This plugin requires immediate attention to address the output escaping issue and implement proper access control checks for any future development.

Key Concerns

  • Unescaped output detected
  • No nonce checks present
  • No capability checks present
Vulnerabilities
None known

Like to Unlock lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Like to Unlock lite Release Timeline

v1.1Current
Code Analysis
Analyzed Mar 16, 2026

Like to Unlock lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface

Like to Unlock lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menujcwp-like-to-unlock-lite.php:40
actionadmin_initjcwp-like-to-unlock-lite.php:46
actionwp_headjcwp-like-to-unlock-lite.php:63
actionwp_footerjcwp-like-to-unlock-lite.php:96
filterthe_contentjcwp-like-to-unlock-lite.php:175
Maintenance & Trust

Like to Unlock lite Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedApr 16, 2015
PHP min version
Downloads4K

Community Trust

Rating60/100
Number of ratings4
Active installs10
Developer Profile

Like to Unlock lite Developer Profile

Jaspreet Chahal

9 plugins · 590 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Like to Unlock lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jcwp-like-to-unlock-lite/application.js
Script Paths
application.js
Version Parameters
jcwp-like-to-unlock-lite/application.js?ver=1.1

HTML / DOM Fingerprints

CSS Classes
jcwp-like-to-unlock
Data Attributes
data-hrefdata-app-iddata-show-facesdata-layoutdata-widthdata-font+1 more
JS Globals
jcorg_ltugpcbjcorgltu_cnv
Shortcode Output
<div class='jcwp-like-to-unlock'><p>
FAQ

Frequently Asked Questions about Like to Unlock lite