[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$frfx-0-rp7YQP4crv9SeFYgRhfhmzKVa3VnHFppzMTRk":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":18,"download_link":25,"security_score":26,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29,"vulnerabilities":30,"developer":31,"crawl_stats":28,"alternatives":35,"analysis":129,"fingerprints":215},"like-and-who-likes","Like And Who Likes","1.3.1","atonyk","https:\u002F\u002Fprofiles.wordpress.org\u002Fatonyk\u002F","\u003Cp>This plugin adds the ‘Like’ button and ‘Who Likes’ list to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WordPress posts and comments\u003C\u002Fli>\n\u003Cli>BuddyPress activities and comments\u003C\u002Fli>\n\u003Cli>BBPress posts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>It allows for registered users to like the items. And it shows for both registered and unregistered users the existing likes.\u003C\u002Fp>\n\u003Cp>The components to show the likes to can be configured on the settings page. For example, the likes can be disabled for WordPress comments.\u003C\u002Fp>\n\u003Cp>Likes are saved in the internal WordPress and BuddyPress meta tables. No separate tables are created.\u003C\u002Fp>\n\u003Cp>The plugin cleans all its data on uninstallation (but not on deactivation).\u003C\u002Fp>\n\u003Cp>You can contribute on – \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fansnap\u002Flike-and-who-likes\" rel=\"nofollow ugc\">https:\u002F\u002Fgithub.com\u002Fansnap\u002Flike-and-who-likes\u003C\u002Fa>\u003C\u002Fp>\n","Adds the 'Like' button and 'Who Likes' list for WordPress, BuddyPress and BBPress.",10,3084,100,1,"2017-05-10T08:11:00.000Z","4.7.32","4.6","",[20,21,22,23,24],"buddypress","like","rate","social","vote","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flike-and-who-likes.1.3.1.zip",85,0,null,"2026-03-15T15:16:48.613Z",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":14,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},30,84,"2026-04-03T23:14:32.029Z",[36,55,74,94,111],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":13,"downloaded":44,"rating":45,"num_ratings":46,"last_updated":47,"tested_up_to":48,"requires_at_least":49,"requires_php":18,"tags":50,"homepage":53,"download_link":54,"security_score":26,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"buddypress-like","BuddyPress Like","0.3.0","darrenmeehan","https:\u002F\u002Fprofiles.wordpress.org\u002Fdarrenmeehan\u002F","\u003Cp>Gives users the ability to ‘like’ content across your BuddyPress enabled site.\u003C\u002Fp>\n","Gives users the ability to 'like' content across your BuddyPress enabled site.",76443,70,26,"2015-12-06T20:41:00.000Z","4.4.34","3.8",[20,21,51,22,52],"post","thumbs","http:\u002F\u002Fdarrenmeehan.me\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbuddypress-like.zip",{"slug":56,"name":57,"version":58,"author":59,"author_profile":60,"description":61,"short_description":62,"active_installs":63,"downloaded":64,"rating":65,"num_ratings":66,"last_updated":18,"tested_up_to":67,"requires_at_least":68,"requires_php":18,"tags":69,"homepage":18,"download_link":72,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":73},"zaki-like-dislike-comments","Zaki Like Dislike Comments","1.2","Riccardo Conte","https:\u002F\u002Fprofiles.wordpress.org\u002Frconte-1\u002F","\u003Cp>This plugin implements a “like\u002Fdislike” rating system for comments. In the setting page you can choose a “compact \u002F splitted” mode that show ratings like sum or separately.\u003C\u002Fp>\n","This plugin implements a \"like\u002Fdislike\" rating system for comments",40,5565,80,5,"4.1.42","3.3",[70,21,71,22,24],"comments","posts","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fzaki-like-dislike-comments.zip","2026-03-15T10:48:56.248Z",{"slug":75,"name":76,"version":77,"author":78,"author_profile":79,"description":80,"short_description":81,"active_installs":11,"downloaded":82,"rating":65,"num_ratings":14,"last_updated":83,"tested_up_to":84,"requires_at_least":85,"requires_php":18,"tags":86,"homepage":92,"download_link":93,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"buddy-share-it-allusers-fb-yr","Share It for All Users on BuddyPress YR","3.4.5","Yuriy Radko","https:\u002F\u002Fprofiles.wordpress.org\u002Fintels\u002F","\u003Cp>This plugin will help you insert different buttons (Share, Like, Viber, Whatsapp, Google and others) into WordPress posts or pages, into Activity or Groups Buddypress. You can select buttons from the initial list: Facebook Share, Facebook Like, Twitter X Share, LinkedIn Share, Digg, WhatsApp Button, Viber Share, Join Viber Community, Viber Group Button, Telegram share, Google search for article title, or search only on the site, Bing search, Yahoo search, Ask search, Duckduckgo search. You can also quickly insert a new custom button for any URL link. Can be used custom icons, images, styles. Works with WordPress or BuddyPress sites. Original code, credit Modemlooper.\u003C\u002Fp>\n\u003Ch3>Notes\u003C\u002Fh3>\n\u003Cp>License.txt – contains the licensing details for this component.\u003C\u002Fp>\n","For generate WP custom buttons, social share, Facebook Like, Buddypress Activity buttons, Viber Whatsapp Telegram Google and other buttons",67438,"2026-03-08T15:11:00.000Z","6.9.4","3.3.1",[87,88,89,90,91],"buddypress-share","custom-button","facebook-like","social-buttons","viber","http:\u002F\u002Fyr.softer.top\u002F2022\u002F12\u002Fshare-it-for-all-users-on-buddypress-yr-wordpress-plugin-free\u002Fyrplugins\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbuddy-share-it-allusers-fb-yr.3.4.5.zip",{"slug":95,"name":96,"version":97,"author":98,"author_profile":99,"description":100,"short_description":101,"active_installs":11,"downloaded":102,"rating":13,"num_ratings":14,"last_updated":18,"tested_up_to":103,"requires_at_least":104,"requires_php":18,"tags":105,"homepage":109,"download_link":110,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":73},"mif-bp-customizer","MIF BP Customizer","1.0.0","asergeev34","https:\u002F\u002Fprofiles.wordpress.org\u002Fasergeev34\u002F","\u003Cp>Buddypress features extension plugin for creation of social network site.\u003Cbr \u002F>\nIt is oriented on work with social networking plugin BuddyPress.\u003C\u002Fp>\n\u003Cp>Adds features:\u003C\u002Fp>\n\u003Cp>Activity feed\u003C\u002Fp>\n\u003Cp>Special activity feed. Changes the appearance and behavior of the activity feed on users’ pages (on personal page – “Whole feed”, on other users’ pages – only their activity). Allows to use content blocking tools.\u003C\u002Fp>\n\u003Cp>Post types of activity feed. Allows to specify activity types, which should be displayed in user’s feed (“Special activity feed” option is required).\u003C\u002Fp>\n\u003Cp>User blocking. Allows to maintain a list of users, whose information is blocked in your activity feed (“Special activity feed” option is required).\u003C\u002Fp>\n\u003Cp>Site behavior\u003C\u002Fp>\n\u003Cp>Profile as a homepage. Set user profile as his home page.\u003C\u002Fp>\n\u003Cp>Profile privacy. Allow users to limit access to their profiles.\u003C\u002Fp>\n\u003Cp>Subscribers. Enable subscription option for user updates (subscription = one-way friendship).\u003C\u002Fp>\n\u003Cp>Notifications. Advanced notification mode.\u003C\u002Fp>\n\u003Cp>Pop-up messages. Mechanism of pop-up messages (echo-server configuration is required).\u003C\u002Fp>\n\u003Cp>Documents. Creation of files and documents collections on users’ and groups’ pages. Files and documents publication in the activity feed.\u003C\u002Fp>\n\u003Cp>Dialogues (experimentally\u002Fis in a test mode). Simple and convenient dialogues instead of the standard system of private messages (experimentally\u002Fis in a test mode; echo-server configuration is required).\u003C\u002Fp>\n\u003Cp>Background image. Allow to use custom image as a background for user profile or group.\u003C\u002Fp>\n\u003Cp>Group address. Allow to change the group address in its settings and at creation.\u003C\u002Fp>\n\u003Cp>«Like» button. «Like» button for posts in the activity feed.\u003C\u002Fp>\n\u003Cp>«Repost» button. Second publication (repost) of posts in the activity feed.\u003C\u002Fp>\n\u003Cp>«Favorite», «Delete» buttons. Special «Favorite», «Delete» buttons (as «Like» and «Repost» button)\u003C\u002Fp>\n\u003Cp>Visual elements\u003C\u002Fp>\n\u003Cp>Site member widget. Fast and simple widget of site members avatars.\u003C\u002Fp>\n\u003Cp>Group widget. Fast and simple widget of group avatars.\u003C\u002Fp>\n","Buddypress features extension plugin for creation of social network site.",1691,"4.9.29","4.8",[20,21,106,107,108],"private-profile","repost","social-network","https:\u002F\u002Fgithub.com\u002Falexey-sergeev\u002Fmif-bp-customizer","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmif-bp-customizer.zip",{"slug":112,"name":113,"version":114,"author":115,"author_profile":116,"description":117,"short_description":118,"active_installs":27,"downloaded":119,"rating":27,"num_ratings":27,"last_updated":120,"tested_up_to":121,"requires_at_least":122,"requires_php":18,"tags":123,"homepage":18,"download_link":127,"security_score":128,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"like-and-dislike","Like and Dislike – like a comment, vote social media post, emoji dislike","1.0","wpcook","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpcook\u002F","\u003Cp>The Like and Dislike plugin adds functionality for users to \u003Cstrong>like\u003C\u002Fstrong> and \u003Cstrong>dislike\u003C\u002Fstrong> posts in WordPress. This allows users to easily express their opinions and engage with content. Users can also \u003Cstrong>like a comment\u003C\u002Fstrong>, making it easier to highlight popular opinions.\u003C\u002Fp>\n\u003Cp>With this plugin, you can enable users to \u003Cstrong>vote on social media posts\u003C\u002Fstrong>, enhancing interaction and feedback. Additionally, the plugin supports \u003Cstrong>emoji dislike\u003C\u002Fstrong>, allowing users to use emojis to express their feelings towards content in a fun and engaging way.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Allow users to \u003Cstrong>like\u003C\u002Fstrong> or \u003Cstrong>dislike\u003C\u002Fstrong> posts.  \u003C\u002Fli>\n\u003Cli>Customize which posts have the voting feature enabled.  \u003C\u002Fli>\n\u003Cli>\u003Cstrong>Vote on posts\u003C\u002Fstrong> with simple buttons, like on \u003Cstrong>social media posts\u003C\u002Fstrong>.  \u003C\u002Fli>\n\u003Cli>Track user interactions using the built-in \u003Cstrong>statistics tab\u003C\u002Fstrong>.  \u003C\u002Fli>\n\u003Cli>Prevent multiple votes from the same user.  \u003C\u002Fli>\n\u003Cli>Emoji-based reactions for more expressive feedback (like\u002Fdislike).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Download the plugin and upload it to your \u003Ccode>\u002Fwp-content\u002Fplugins\u002F\u003C\u002Fcode> directory.\u003C\u002Fli>\n\u003Cli>Activate the plugin through the ‘Plugins’ menu in WordPress.\u003C\u002Fli>\n\u003Cli>Configure settings under the “Like and Dislike” admin menu.\u003C\u002Fli>\n\u003C\u002Fol>\n","Short Description: A plugin that allows users to like and dislike posts in WordPress.",414,"2025-01-21T11:56:00.000Z","6.7.5","5.0",[124,21,125,126,24],"dislike","like-a-comment","social-media-post","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flike-and-dislike.1.0.zip",92,{"attackSurface":130,"codeSignals":185,"taintFlows":203,"riskAssessment":204,"analyzedAt":214},{"hooks":131,"ajaxHandlers":176,"restRoutes":182,"shortcodes":183,"cronEvents":184,"entryPointCount":14,"unprotectedCount":14},[132,137,141,147,151,155,158,162,166,169,172],{"type":133,"name":134,"callback":134,"file":135,"line":136},"action","admin_menu","includes\\class-who-likes-settings.php",12,{"type":133,"name":138,"callback":139,"file":135,"line":140},"admin_init","settings_init",13,{"type":142,"name":143,"callback":144,"file":145,"line":146},"filter","the_content","add_likes_to_wp_posts","includes\\class-who-likes.php",24,{"type":142,"name":148,"callback":149,"priority":11,"file":145,"line":150},"comment_reply_link_args","add_likes_to_wp_comments",28,{"type":133,"name":152,"callback":153,"file":145,"line":154},"bp_activity_entry_meta","add_likes_to_bp_activities",33,{"type":133,"name":156,"callback":153,"file":145,"line":157},"bp_activity_entry_content",34,{"type":133,"name":159,"callback":160,"file":145,"line":161},"bp_activity_comment_options","add_likes_to_bp_comments",38,{"type":142,"name":163,"callback":164,"priority":11,"file":145,"line":165},"bbp_topic_admin_links","add_likes_to_bbp_posts",43,{"type":142,"name":167,"callback":164,"priority":11,"file":145,"line":168},"bbp_reply_admin_links",44,{"type":133,"name":170,"callback":164,"file":145,"line":171},"bbp_theme_after_reply_content",45,{"type":133,"name":173,"callback":174,"file":145,"line":175},"wp_enqueue_scripts","add_assets",49,[177],{"action":178,"nopriv":179,"callback":180,"hasNonce":179,"hasCapCheck":179,"file":145,"line":181},"like_and_who_likes",false,"ajax_action",50,[],[],[],{"dangerousFunctions":186,"sqlUsage":187,"outputEscaping":189,"fileOperations":27,"externalRequests":27,"nonceChecks":27,"capabilityChecks":27,"bundledLibraries":202},[],{"prepared":27,"raw":27,"locations":188},[],{"escaped":190,"rawEcho":191,"locations":192},6,4,[193,196,198,200],{"file":145,"line":194,"context":195},91,"raw output",{"file":145,"line":197,"context":195},93,{"file":145,"line":199,"context":195},103,{"file":145,"line":201,"context":195},113,[],[],{"summary":205,"deductions":206},"The \"like-and-who-likes\" plugin version 1.3.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by not using dangerous functions, performing all SQL queries with prepared statements, having no file operations, no external HTTP requests, and no bundled libraries, which reduces the attack surface from common vulnerabilities. The absence of any recorded historical vulnerabilities is also a positive indicator.\n\nHowever, significant concerns arise from the static analysis. The plugin has a single entry point through an AJAX handler, and critically, this handler lacks authentication checks. This means any unauthenticated user can potentially interact with this endpoint, which is a major security risk. Furthermore, while the total number of outputs is small, 40% of them are not properly escaped, potentially leading to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is reflected in these outputs.\n\nWhile there's no recorded vulnerability history, the presence of an unprotected AJAX handler and unescaped output represents a substantial risk that could be exploited. The lack of nonce checks also contributes to the overall insecurity of the AJAX endpoint. In conclusion, despite some good security practices, the unprotected AJAX endpoint and insufficient output escaping are critical weaknesses that require immediate attention.",[207,209,212],{"reason":208,"points":11},"Unprotected AJAX handler",{"reason":210,"points":211},"Missing nonce checks",7,{"reason":213,"points":66},"Unescaped output (40%)","2026-03-17T01:19:40.867Z",{"wat":216,"direct":225},{"assetPaths":217,"generatorPatterns":220,"scriptPaths":221,"versionParams":222},[218,219],"\u002Fwp-content\u002Fplugins\u002Flike-and-who-likes\u002Fjs\u002Flike-and-who-likes.js","\u002Fwp-content\u002Fplugins\u002Flike-and-who-likes\u002Fcss\u002Flike-and-who-likes.css",[],[218],[223,224],"like-and-who-likes\u002Fjs\u002Flike-and-who-likes.js?ver=","like-and-who-likes\u002Fcss\u002Flike-and-who-likes.css?ver=",{"cssClasses":226,"htmlComments":230,"htmlAttributes":231,"restEndpoints":234,"jsGlobals":236,"shortcodeOutput":238},[227,228,229],"wl-like","wl-unlike","wl-list",[],[232,233],"data-id","data-component",[235],"\u002Fwp-admin\u002Fadmin-ajax.php",[237],"who_likes",[]]