
Like Share Zalo Button Security & Risk Analysis
wordpress.org/plugins/like-share-zalo-buttonDisplays Zalo like/share button in post content. Zalo is The most popular mobile social network in Vietnam.
Is Like Share Zalo Button Safe to Use in 2026?
Generally Safe
Score 85/100Like Share Zalo Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "like-share-zalo-button" v1.0.1 plugin exhibits a remarkably clean static analysis report, with no identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication. Furthermore, the code signals show a complete absence of dangerous functions, SQL queries executed without prepared statements, file operations, or external HTTP requests. This suggests a plugin that has been developed with a strong emphasis on security best practices, minimizing the potential for common web vulnerabilities.
However, a significant concern arises from the complete lack of nonce checks and capability checks across the board. While the current version has no identified vulnerabilities or CVEs, this absence of fundamental security mechanisms leaves the plugin exposed to potential Cross-Site Request Forgery (CSRF) attacks or unauthorized access if any entry points were to be introduced or discovered in future updates. The taint analysis also shows no flows analyzed, which, while not a direct risk, means that complex data manipulation pathways haven't been thoroughly examined for sanitization issues. The vulnerability history being completely clear is a positive indicator, suggesting a well-maintained or very simple plugin, but the lack of security checks remains a notable weakness.
In conclusion, the plugin is currently in a very secure state due to its limited attack surface and adherence to secure coding practices regarding data handling. The lack of known vulnerabilities is highly encouraging. Nevertheless, the absence of nonce and capability checks represents a critical gap that could be exploited if the plugin's surface area expands or if an attacker finds an indirect way to trigger its functionality. Developers should prioritize implementing these checks to solidify its security posture.
Key Concerns
- Missing nonce checks
- Missing capability checks
Like Share Zalo Button Security Vulnerabilities
Like Share Zalo Button Code Analysis
Output Escaping
Like Share Zalo Button Attack Surface
WordPress Hooks 4
Maintenance & Trust
Like Share Zalo Button Maintenance & Trust
Maintenance Signals
Community Trust
Like Share Zalo Button Alternatives
Simple Share Buttons Adder
simple-share-buttons-adder
A simple plugin that enables you to add share buttons to all of your posts and/or pages.
ShareThis Share Buttons
sharethis-share-buttons
Grow your website traffic and engagement by enabling one-click sharing with the free ShareThis Share Buttons plugin. The plugin is free (no upgrades a …
Simple Social Media Share Buttons – Social Sharing for Everyone
simple-social-buttons
This Social Share Plugin adds advanced social media sharing buttons to your WordPress sites, such as Facebook, WhatsApp, X, LinkedIn, & Pinterest.
BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress
facebook-button-plugin
Add Facebook Follow, Like, and Share buttons to WordPress posts, pages, and widgets.
Cresta Social Share Counter
cresta-social-share-counter
Share your posts and pages quickly and easily with Cresta Social Share Counter and show share counts.
Like Share Zalo Button Developer Profile
2 plugins · 130 total installs
How We Detect Like Share Zalo Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/like-share-zalo-button/images/data-layout-demo.jpghttps://sp.zalo.me/plugins/sdk.jsHTML / DOM Fingerprints
zalo-share-buttondata-hrefdata-oaiddata-layoutdata-colordata-customize<div class="zalo-share-button" data-href="