Web3Press – Migrating to 3ook.com Decentralized Bookstore Security & Risk Analysis

wordpress.org/plugins/likecoin

FINAL LEGACY VERSION: Read-only maintenance version before 3ook.com transition. No new publishing features.

500 active installs v4.0.0 PHP 5.4+ WP 5.3+ Updated Sep 4, 2025
blockchainbooksdecentralizedpublishingweb3
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 2, 2025
Safety Verdict

Is Web3Press – Migrating to 3ook.com Decentralized Bookstore Safe to Use in 2026?

Generally Safe

Score 99/100

Web3Press – Migrating to 3ook.com Decentralized Bookstore has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 2, 2025Updated 7mo ago
Risk Assessment

The static analysis of the 'likecoin' v4.0.0 plugin indicates a generally good security posture. All identified entry points, including AJAX handlers and REST API routes, appear to have proper authorization checks in place. The code also demonstrates strong adherence to secure coding practices, with 100% of SQL queries using prepared statements and all output properly escaped. The absence of critical or high severity taint analysis findings is also a positive sign. However, the presence of a single medium severity vulnerability in its history, specifically a 'Path Traversal' issue, warrants attention. While currently patched according to the data, it suggests a past weakness that could be exploited if not diligently managed. The plugin also performs one file operation and one external HTTP request, which, while not inherently risky, are potential vectors that require careful scrutiny in any security audit.

Key Concerns

  • Past medium severity vulnerability (Path Traversal)
Vulnerabilities
1

Web3Press – Migrating to 3ook.com Decentralized Bookstore Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-46527medium · 6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Web3Press <= 3.2.0 - Authenticated (Contributor+) Arbitrary File Read

May 2, 2025 Patched in 3.3.0 (7d)
Code Analysis
Analyzed Mar 16, 2026

Web3Press – Migrating to 3ook.com Decentralized Bookstore Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
31 escaped
Nonce Checks
2
Capability Checks
13
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped31 total outputs
Attack Surface

Web3Press – Migrating to 3ook.com Decentralized Bookstore Attack Surface

Entry Points15
Unprotected0

AJAX Handlers 1

authwp_ajax_likecoin_get_error_noticeadmin\class-likecoin-ajax.php:43

REST API Routes 13

GET/wp-json/likecoin/v1/options/liker-idadmin\class-likecoin-restful.php:92
POST/wp-json/likecoin/v1/options/liker-idadmin\class-likecoin-restful.php:104
GET/wp-json/likecoin/v1/options/liker-id/useradmin\class-likecoin-restful.php:117
POST/wp-json/likecoin/v1/options/liker-id/useradmin\class-likecoin-restful.php:129
GET/wp-json/likecoin/v1/option/publishadmin\class-likecoin-restful.php:142
POST/wp-json/likecoin/v1/option/publishadmin\class-likecoin-restful.php:154
GET/wp-json/likecoin/v1/option/web-monetizationadmin\class-likecoin-restful.php:167
POST/wp-json/likecoin/v1/option/web-monetizationadmin\class-likecoin-restful.php:179
GET/wp-json/likecoin/v1/posts/(?P<id>\d+)/button/settingsadmin\class-likecoin-restful.php:192
POST/wp-json/likecoin/v1/posts/(?P<id>\d+)/button/settingsadmin\class-likecoin-restful.php:207
POST/wp-json/likecoin/v1/posts/(?P<id>\d+)/iscn/arweaveadmin\class-likecoin-restful.php:222
POST/wp-json/likecoin/v1/posts/(?P<id>\d+)/iscn/metadataadmin\class-likecoin-restful.php:237
GET/wp-json/likecoin/v1/posts/(?P<id>\d+)/iscn/metadataadmin\class-likecoin-restful.php:252

Shortcodes 1

[likecoin] includes\class-likecoin-public.php:75
WordPress Hooks 19
actionadmin_menuadmin\class-likecoin-admin.php:87
actionadmin_initadmin\class-likecoin-admin.php:88
actionsave_post_postadmin\class-likecoin-admin.php:90
actionsave_post_pageadmin\class-likecoin-admin.php:91
actionenqueue_block_editor_assetsadmin\class-likecoin-admin.php:92
actionadmin_noticesadmin\class-likecoin-admin.php:93
actionadmin_noticesadmin\class-likecoin-admin.php:94
actionadmin_post_likecoin_update_user_idadmin\class-likecoin-ajax.php:42
actionpublish_postadmin\class-likecoin-internet-archive.php:94
actionrest_api_initadmin\class-likecoin-restful.php:277
actionupgrader_process_completeincludes\class-likecoin-loader.php:182
actioninitincludes\class-likecoin-loader.php:183
actioninitincludes\class-likecoin-loader.php:184
actionplugins_loadedincludes\class-likecoin-loader.php:185
actionactivated_pluginincludes\class-likecoin-loader.php:186
filterthe_contentincludes\class-likecoin-public.php:72
actionwp_headincludes\class-likecoin-public.php:73
actionwp_headincludes\class-likecoin-public.php:74
filterhttp_request_timeoutincludes\class-likecoin-public.php:76
Maintenance & Trust

Web3Press – Migrating to 3ook.com Decentralized Bookstore Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 4, 2025
PHP min version5.4
Downloads65K

Community Trust

Rating100/100
Number of ratings10
Active installs500
Developer Profile

Web3Press – Migrating to 3ook.com Decentralized Bookstore Developer Profile

LikeCoin

1 plugin · 500 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Web3Press – Migrating to 3ook.com Decentralized Bookstore

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/likecoin/assets/js/sidebar/index.js/wp-content/plugins/likecoin/assets/js/sidebar/index.css
Script Paths
/wp-content/plugins/likecoin/assets/js/sidebar/index.js
Version Parameters
likecoin/style.css?ver=likecoin-sidebar-js?ver=likecoin-sidebar-css?ver=

HTML / DOM Fingerprints

Data Attributes
data-likecoin-widget-enableddata-likecoin-show-no-id-error
JS Globals
likecoinApiSettings
FAQ

Frequently Asked Questions about Web3Press – Migrating to 3ook.com Decentralized Bookstore