Likes System and Social Share Buttons for WordPress and WooCommerce Security & Risk Analysis

wordpress.org/plugins/likes-and-share-system-free

Standalone likes system and social share buttons for your website. Custom post types are supported! Working with WooCommerce as well.

0 active installs v1.1 PHP 5.4+ WP 3.4.0+ Updated Aug 2, 2020
buttonsbuttons-for-wordpressbuttons-for-wordpress-and-woocommercelikes-systemsocial-share-buttons
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Likes System and Social Share Buttons for WordPress and WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Likes System and Social Share Buttons for WordPress and WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "likes-and-share-system-free" plugin v1.1 exhibits several security concerns that necessitate careful consideration. While the absence of known CVEs and a low percentage of raw SQL queries are positive indicators, significant weaknesses are present in its attack surface and code sanitization practices. The presence of two unprotected AJAX handlers represents a direct pathway for potential unauthorized actions if these handlers are exploitable. Furthermore, the taint analysis reveals two high-severity flows with unsanitized paths, strongly suggesting the possibility of injection vulnerabilities. The low percentage of properly escaped output (30%) is also a major red flag, increasing the risk of cross-site scripting (XSS) attacks. The lack of nonce and capability checks on entry points, coupled with the bundled Select2 library (which could potentially be outdated and vulnerable), further exacerbates the security risks. In conclusion, while the plugin avoids historical vulnerabilities and manages SQL queries reasonably well, its static analysis points to critical weaknesses in input validation and output escaping, making it a moderate to high risk without further investigation and remediation.

Key Concerns

  • Unprotected AJAX handlers found
  • High severity taint flows with unsanitized paths
  • Low percentage of properly escaped output
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Bundled library (Select2) may be outdated
Vulnerabilities
None known

Likes System and Social Share Buttons for WordPress and WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Likes System and Social Share Buttons for WordPress and WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
7 prepared
Unescaped Output
75
32 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

88% prepared8 total queries

Output Escaping

30% escaped107 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
get_likes_response_ajax (classes\LikesAndShareSystem.php:177)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Likes System and Social Share Buttons for WordPress and WooCommerce Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 2

authwp_ajax_likesresponseclasses\LikesAndShareSystem.php:39
noprivwp_ajax_likesresponseclasses\LikesAndShareSystem.php:40

Shortcodes 2

[lass_system_archive] classes\LikesAndShareSystem.php:25
[lass_system] classes\LikesAndShareSystem.php:26
WordPress Hooks 9
actionadmin_menuclasses\Dashboard.php:13
actionadmin_initclasses\Dashboard.php:16
filterthe_contentclasses\LikesAndShareSystem.php:29
filterthe_excerptclasses\LikesAndShareSystem.php:30
actionwp_enqueue_scriptsclasses\LikesAndShareSystem.php:34
actionwp_enqueue_scriptsclasses\LikesAndShareSystem.php:35
actionadmin_enqueue_scriptsclasses\LikesAndShareSystem.php:36
actionadmin_noticeslikes-share-system-free.php:18
actionadmin_noticeslikes-share-system-free.php:25
Maintenance & Trust

Likes System and Social Share Buttons for WordPress and WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 2, 2020
PHP min version5.4
Downloads914

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Likes System and Social Share Buttons for WordPress and WooCommerce Developer Profile

Albin

2 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Likes System and Social Share Buttons for WordPress and WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/likes-and-share-system-free/assets/front/css/likes-share-system.css/wp-content/plugins/likes-and-share-system-free/assets/front/js/likes-share-system.js/wp-content/plugins/likes-and-share-system-free/assets/front/fontawesome/css/font-awesome.min.css/wp-content/plugins/likes-and-share-system-free/assets/admin/css/likes-share-system.css/wp-content/plugins/likes-and-share-system-free/assets/admin/js/likes-share-system.js/wp-content/plugins/likes-and-share-system-free/assets/admin/colorpicker/css/colorpicker.css/wp-content/plugins/likes-and-share-system-free/assets/admin/colorpicker/js/colorpicker.js
Script Paths
/wp-content/plugins/likes-and-share-system-free/assets/front/js/likes-share-system.js/wp-content/plugins/likes-and-share-system-free/assets/admin/js/likes-share-system.js/wp-content/plugins/likes-and-share-system-free/assets/admin/colorpicker/js/colorpicker.js
Version Parameters
/wp-content/plugins/likes-and-share-system-free/assets/front/fontawesome/css/font-awesome.min.css?ver=4.7.0

HTML / DOM Fingerprints

CSS Classes
lass-like-share-stylelass-like-share-systemlass-like-share-buttonslass-frontend-likes-wrapperlass-icon-share
Data Attributes
data-post-id
JS Globals
wpp
Shortcode Output
[lass_system_archive][lass_system]
FAQ

Frequently Asked Questions about Likes System and Social Share Buttons for WordPress and WooCommerce