
Like And Who Likes Security & Risk Analysis
wordpress.org/plugins/like-and-who-likesAdds the 'Like' button and 'Who Likes' list for WordPress, BuddyPress and BBPress.
Is Like And Who Likes Safe to Use in 2026?
Generally Safe
Score 85/100Like And Who Likes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "like-and-who-likes" plugin version 1.3.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by not using dangerous functions, performing all SQL queries with prepared statements, having no file operations, no external HTTP requests, and no bundled libraries, which reduces the attack surface from common vulnerabilities. The absence of any recorded historical vulnerabilities is also a positive indicator.
However, significant concerns arise from the static analysis. The plugin has a single entry point through an AJAX handler, and critically, this handler lacks authentication checks. This means any unauthenticated user can potentially interact with this endpoint, which is a major security risk. Furthermore, while the total number of outputs is small, 40% of them are not properly escaped, potentially leading to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is reflected in these outputs.
While there's no recorded vulnerability history, the presence of an unprotected AJAX handler and unescaped output represents a substantial risk that could be exploited. The lack of nonce checks also contributes to the overall insecurity of the AJAX endpoint. In conclusion, despite some good security practices, the unprotected AJAX endpoint and insufficient output escaping are critical weaknesses that require immediate attention.
Key Concerns
- Unprotected AJAX handler
- Missing nonce checks
- Unescaped output (40%)
Like And Who Likes Security Vulnerabilities
Like And Who Likes Code Analysis
Output Escaping
Like And Who Likes Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Maintenance & Trust
Like And Who Likes Maintenance & Trust
Maintenance Signals
Community Trust
Like And Who Likes Alternatives
BuddyPress Like
buddypress-like
Gives users the ability to 'like' content across your BuddyPress enabled site.
Zaki Like Dislike Comments
zaki-like-dislike-comments
This plugin implements a "like/dislike" rating system for comments
Share It for All Users on BuddyPress YR
buddy-share-it-allusers-fb-yr
For generate WP custom buttons, social share, Facebook Like, Buddypress Activity buttons, Viber Whatsapp Telegram Google and other buttons
MIF BP Customizer
mif-bp-customizer
Buddypress features extension plugin for creation of social network site.
Like and Dislike – like a comment, vote social media post, emoji dislike
like-and-dislike
Short Description: A plugin that allows users to like and dislike posts in WordPress.
Like And Who Likes Developer Profile
1 plugin · 10 total installs
How We Detect Like And Who Likes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/like-and-who-likes/js/like-and-who-likes.js/wp-content/plugins/like-and-who-likes/css/like-and-who-likes.css/wp-content/plugins/like-and-who-likes/js/like-and-who-likes.jslike-and-who-likes/js/like-and-who-likes.js?ver=like-and-who-likes/css/like-and-who-likes.css?ver=HTML / DOM Fingerprints
wl-likewl-unlikewl-listdata-iddata-componentwho_likes/wp-admin/admin-ajax.php