Like Cheese Security & Risk Analysis

wordpress.org/plugins/likecheese

Like Cheese lets your site visitors 'like' your site images.

10 active installs v2.0 PHP + WP 3.0+ Updated Dec 4, 2016
funimagesinstagramlikes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Like Cheese Safe to Use in 2026?

Generally Safe

Score 85/100

Like Cheese has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The 'likecheese' v2.0 plugin exhibits a strong security posture based on the provided static analysis. A significant strength is the complete absence of dangerous functions, raw SQL queries, and unescaped output. All SQL queries utilize prepared statements, and all identified output is properly escaped, which are critical good practices for preventing common web vulnerabilities. The presence of a nonce check on its single AJAX handler further bolsters its security by mitigating CSRF attacks. The lack of any recorded vulnerability history, including CVEs, suggests a history of secure development or effective patching.

While the static analysis reveals no immediate critical vulnerabilities such as unsanitized taint flows or raw SQL, the limited attack surface is entirely protected by a nonce check on its sole AJAX handler. However, a notable concern is the complete absence of capability checks on this entry point. This means any authenticated user, regardless of their role or permissions, can trigger the AJAX action. This could lead to unintended functionality or even privilege escalation if the AJAX action performs sensitive operations. The plugin's overall security is good, but this lack of granular access control on the AJAX handler represents a potential weakness that could be exploited in certain contexts.

Key Concerns

  • AJAX handler missing capability checks
Vulnerabilities
None known

Like Cheese Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Like Cheese Release Timeline

v2.0Current
v1.5.4
Code Analysis
Analyzed Apr 16, 2026

Like Cheese Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
8 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped8 total outputs
Attack Surface

Like Cheese Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_likecheese_ali_ajax_like_imagelike-cheese.php:269
WordPress Hooks 10
actiontemplate_redirectlike-cheese.php:23
filterthe_contentlike-cheese.php:181
filterattachment_fields_to_editlike-cheese.php:195
filterattachment_fields_to_savelike-cheese.php:202
filterattachment_fields_to_editlike-cheese.php:213
filterattachment_fields_to_savelike-cheese.php:220
filterattachment_fields_to_editlike-cheese.php:233
filterattachment_fields_to_savelike-cheese.php:240
filterattachment_fields_to_editlike-cheese.php:253
filterattachment_fields_to_savelike-cheese.php:260
Maintenance & Trust

Like Cheese Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedDec 4, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Like Cheese Developer Profile

sageshilling

3 plugins · 20 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Like Cheese

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/likecheese/css/style.css/wp-content/plugins/likecheese/js/ajax_like_image.js
Version Parameters
likecheese-stylelikecheese_ajax_like_image

HTML / DOM Fingerprints

CSS Classes
likecheese_ali_likeelizabethneedsabignap
Data Attributes
data-iddata-likecheeseusernamedata-noncedata-sitepath
JS Globals
likecheese_params
FAQ

Frequently Asked Questions about Like Cheese