
Like Posts & Comments Security & Risk Analysis
wordpress.org/plugins/likes-posts-commentsAllows you to add links 'I like / I do not like' to each post and comment.
Is Like Posts & Comments Safe to Use in 2026?
Generally Safe
Score 85/100Like Posts & Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "likes-posts-comments" v1.1 plugin presents a concerning security posture despite some positive aspects. While it avoids dangerous functions, raw SQL queries, and external HTTP requests, its attack surface is significantly exposed. The presence of two AJAX handlers without any authentication or capability checks is a critical vulnerability, allowing unauthenticated users to potentially trigger plugin functionalities. The taint analysis further highlights this risk, revealing three high-severity flows with unsanitized paths, strongly suggesting these AJAX endpoints are susceptible to injection attacks. The lack of nonce checks on these AJAX actions exacerbates the problem, making cross-site request forgery (CSRF) attacks highly probable. Furthermore, only 21% of output is properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities. The plugin's vulnerability history is clean, indicating a lack of past exploitable issues, which is positive. However, this historical data does not mitigate the immediate and significant risks identified in the current code analysis. The plugin's overall security is weak due to its exposed attack surface and lack of fundamental security checks.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows (unsanitized paths)
- Missing nonce checks
- Low output escaping percentage
Like Posts & Comments Security Vulnerabilities
Like Posts & Comments Release Timeline
Like Posts & Comments Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Like Posts & Comments Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Maintenance & Trust
Like Posts & Comments Maintenance & Trust
Maintenance Signals
Community Trust
Like Posts & Comments Alternatives
Like Post Block
like-post-block
Add a button to like any post type.
CleverNode Related Content
clevernode-related-content
CleverNode Related Content is a semantic correlation service that allows you to place a collection of related articles on your WordPress site.
Post Like Manager
pl-manager
A smooth ajax-based like/dislike functionality for wordpress posts, pages, Custom post types..
Post Like
post-like
Post like is a simple ajax based post like/unlike plugin that help your visitors to like posts. Counter shows number of post likes.
Post Likerator
post-likerator
Simple like/unlike function for posts. No dislikes. Bring your own CSS.
Like Posts & Comments Developer Profile
10 plugins · 78K total installs
How We Detect Like Posts & Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/likes-posts-comments/css/style.css/wp-content/plugins/likes-posts-comments/js/likes.js/wp-content/plugins/likes-posts-comments/js/likes.jslikes-posts-comments/css/style.css?ver=likes-posts-comments/js/likes.js?ver=HTML / DOM Fingerprints
likes-post-linkdolikedoUnlikelikes-comment-linknb-likes-postnb-likes-commentrel="postID_rel="commentID_var ajax_url = '