Like Share Zalo Button Security & Risk Analysis

wordpress.org/plugins/like-share-zalo-button

Displays Zalo like/share button in post content. Zalo is The most popular mobile social network in Vietnam.

100 active installs v1.0.1 PHP 5.4+ WP 4.6+ Updated Dec 28, 2017
share-buttonsocialsocial-buttonzalo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Like Share Zalo Button Safe to Use in 2026?

Generally Safe

Score 85/100

Like Share Zalo Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "like-share-zalo-button" v1.0.1 plugin exhibits a remarkably clean static analysis report, with no identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication. Furthermore, the code signals show a complete absence of dangerous functions, SQL queries executed without prepared statements, file operations, or external HTTP requests. This suggests a plugin that has been developed with a strong emphasis on security best practices, minimizing the potential for common web vulnerabilities.

However, a significant concern arises from the complete lack of nonce checks and capability checks across the board. While the current version has no identified vulnerabilities or CVEs, this absence of fundamental security mechanisms leaves the plugin exposed to potential Cross-Site Request Forgery (CSRF) attacks or unauthorized access if any entry points were to be introduced or discovered in future updates. The taint analysis also shows no flows analyzed, which, while not a direct risk, means that complex data manipulation pathways haven't been thoroughly examined for sanitization issues. The vulnerability history being completely clear is a positive indicator, suggesting a well-maintained or very simple plugin, but the lack of security checks remains a notable weakness.

In conclusion, the plugin is currently in a very secure state due to its limited attack surface and adherence to secure coding practices regarding data handling. The lack of known vulnerabilities is highly encouraging. Nevertheless, the absence of nonce and capability checks represents a critical gap that could be exploited if the plugin's surface area expands or if an attacker finds an indirect way to trigger its functionality. Developers should prioritize implementing these checks to solidify its security posture.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Like Share Zalo Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Like Share Zalo Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped3 total outputs
Attack Surface

Like Share Zalo Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_enqueue_scriptslike-share-zalo-button.php:19
actionadmin_initlike-share-zalo-button.php:25
actionadmin_menulike-share-zalo-button.php:30
filterthe_contentlike-share-zalo-button.php:61
Maintenance & Trust

Like Share Zalo Button Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedDec 28, 2017
PHP min version5.4
Downloads15K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Like Share Zalo Button Developer Profile

Kimi

2 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Like Share Zalo Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/like-share-zalo-button/images/data-layout-demo.jpg
Script Paths
https://sp.zalo.me/plugins/sdk.js

HTML / DOM Fingerprints

CSS Classes
zalo-share-button
Data Attributes
data-hrefdata-oaiddata-layoutdata-colordata-customize
Shortcode Output
<div class="zalo-share-button" data-href="
FAQ

Frequently Asked Questions about Like Share Zalo Button