
Likes System and Social Share Buttons for WordPress and WooCommerce Security & Risk Analysis
wordpress.org/plugins/likes-and-share-system-freeStandalone likes system and social share buttons for your website. Custom post types are supported! Working with WooCommerce as well.
Is Likes System and Social Share Buttons for WordPress and WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Likes System and Social Share Buttons for WordPress and WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "likes-and-share-system-free" plugin v1.1 exhibits several security concerns that necessitate careful consideration. While the absence of known CVEs and a low percentage of raw SQL queries are positive indicators, significant weaknesses are present in its attack surface and code sanitization practices. The presence of two unprotected AJAX handlers represents a direct pathway for potential unauthorized actions if these handlers are exploitable. Furthermore, the taint analysis reveals two high-severity flows with unsanitized paths, strongly suggesting the possibility of injection vulnerabilities. The low percentage of properly escaped output (30%) is also a major red flag, increasing the risk of cross-site scripting (XSS) attacks. The lack of nonce and capability checks on entry points, coupled with the bundled Select2 library (which could potentially be outdated and vulnerable), further exacerbates the security risks. In conclusion, while the plugin avoids historical vulnerabilities and manages SQL queries reasonably well, its static analysis points to critical weaknesses in input validation and output escaping, making it a moderate to high risk without further investigation and remediation.
Key Concerns
- Unprotected AJAX handlers found
- High severity taint flows with unsanitized paths
- Low percentage of properly escaped output
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Bundled library (Select2) may be outdated
Likes System and Social Share Buttons for WordPress and WooCommerce Security Vulnerabilities
Likes System and Social Share Buttons for WordPress and WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Likes System and Social Share Buttons for WordPress and WooCommerce Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
Likes System and Social Share Buttons for WordPress and WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Likes System and Social Share Buttons for WordPress and WooCommerce Alternatives
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
Custom Share Buttons with Floating Sidebar
custom-share-buttons-with-floating-sidebar
Share buttons with extra features to sharing your website posts/pages on Facebook, Twitter, Instagram, Whatsapp, Pinterest etc.
Social Rocket – Social Sharing Plugin
social-rocket
Add fully-customizable social sharing buttons to your site. Easy to use and packed with many additional social networking features.
Social Share Button
social-share-button
Awesome Share Button
Highlight and Share – Unobtrusive and Lightweight Content Sharing
highlight-and-share
A lightweight social sharing plugin for showing social networks when users highlight text, share images, headlines, or use Click to Share.
Likes System and Social Share Buttons for WordPress and WooCommerce Developer Profile
2 plugins · 0 total installs
How We Detect Likes System and Social Share Buttons for WordPress and WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/likes-and-share-system-free/assets/front/css/likes-share-system.css/wp-content/plugins/likes-and-share-system-free/assets/front/js/likes-share-system.js/wp-content/plugins/likes-and-share-system-free/assets/front/fontawesome/css/font-awesome.min.css/wp-content/plugins/likes-and-share-system-free/assets/admin/css/likes-share-system.css/wp-content/plugins/likes-and-share-system-free/assets/admin/js/likes-share-system.js/wp-content/plugins/likes-and-share-system-free/assets/admin/colorpicker/css/colorpicker.css/wp-content/plugins/likes-and-share-system-free/assets/admin/colorpicker/js/colorpicker.js/wp-content/plugins/likes-and-share-system-free/assets/front/js/likes-share-system.js/wp-content/plugins/likes-and-share-system-free/assets/admin/js/likes-share-system.js/wp-content/plugins/likes-and-share-system-free/assets/admin/colorpicker/js/colorpicker.js/wp-content/plugins/likes-and-share-system-free/assets/front/fontawesome/css/font-awesome.min.css?ver=4.7.0HTML / DOM Fingerprints
lass-like-share-stylelass-like-share-systemlass-like-share-buttonslass-frontend-likes-wrapperlass-icon-sharedata-post-idwpp[lass_system_archive][lass_system]