
Lotos Likes Security & Risk Analysis
wordpress.org/plugins/lotos-likesAdd "like" functionality to your posts and pages
Is Lotos Likes Safe to Use in 2026?
Generally Safe
Score 100/100Lotos Likes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lotos-likes" v1.8 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerabilities. This suggests a developer who is aware of some fundamental security principles. However, significant concerns arise from the static analysis. The plugin has a total of 3 entry points, with 2 of them being AJAX handlers that completely lack authentication checks. This is a critical oversight, exposing these handlers to potential abuse by unauthenticated users. Furthermore, only a small percentage (14%) of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities across its various output mechanisms. The taint analysis also reveals 2 flows with unsanitized paths, which, although not classified as critical or high severity in this analysis, still represent potential avenues for malicious input to reach sensitive parts of the code. The lack of nonce checks and capability checks on critical entry points compounds the risk associated with the unprotected AJAX handlers.
Key Concerns
- Unprotected AJAX handlers
- Low output escaping percentage
- Taint flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
Lotos Likes Security Vulnerabilities
Lotos Likes Code Analysis
Output Escaping
Data Flow Analysis
Lotos Likes Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Lotos Likes Maintenance & Trust
Maintenance Signals
Community Trust
Lotos Likes Alternatives
WP Post Likes
wp-post-likes
A simple and efficient post like system for WordPress.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Lotos Likes Developer Profile
1 plugin · 200 total installs
How We Detect Lotos Likes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lotos-likes/css/lotos-likes.css/wp-content/plugins/lotos-likes/js/lotos-likes.js/wp-content/plugins/lotos-likes/js/lotos-likes.jslotos-likes/css/lotos-likes.css?ver=lotos-likes/js/lotos-likes.js?ver=HTML / DOM Fingerprints
lotos-likes-countlotos-likes-buttondata-post-iddata-likes-countlotosLikes/wp-json/lotos-likes/v1/likes[lotos_likes]