
Love It Security & Risk Analysis
wordpress.org/plugins/love-itLove It is a simple plugin that adds a "Love It" link to your posts, pages, and custom post types. Show your most popular items in a widget.
Is Love It Safe to Use in 2026?
Generally Safe
Score 85/100Love It has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "love-it" plugin v1.0.5 exhibits a mixed security posture. On the positive side, it has a very small attack surface with only one AJAX handler and no shortcodes, cron events, or REST API routes. Crucially, this single AJAX handler does have a nonce check, and all SQL queries are properly prepared. There is also no recorded vulnerability history, suggesting a generally well-maintained codebase in the past. However, several concerning signals are present in the static analysis. The use of the `create_function` is a significant red flag, as it can lead to code injection vulnerabilities if not handled with extreme care. Furthermore, a very low percentage (17%) of output escaping suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied data may be outputted directly into the page without proper sanitization. The absence of capability checks on the AJAX handler, while having a nonce, leaves a potential for privilege escalation if the nonce check is bypassed or if sensitive actions are performed without verifying user roles.
Key Concerns
- Dangerous function create_function used
- Low output escaping percentage (17%)
- Missing capability checks on AJAX handler
Love It Security Vulnerabilities
Love It Code Analysis
Dangerous Functions Found
Output Escaping
Love It Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Love It Maintenance & Trust
Maintenance Signals
Community Trust
Love It Alternatives
I Recommend This – Love/Like Button for WordPress Posts
i-recommend-this
Enable your visitors to easily like or recommend your posts with a single click, enhancing engagement without the need for comments.
Love Me
love-me
Display a very simple and customisable like button for your posts or any custom post type.
Love Button
love-button
Add a Twitter style love/like/upvote button to your content.
Post Reaction – Add Like or Emoji Reactions to Posts
post-reaction
Add Facebook Reaction interface in WordPress Posts and Count them (likes, loves, cares, custom react)
Like to Unlock lite
jcwp-like-to-unlock-lite
This plugin gives you control to initially hide part of your article from user. Content is displayed correctly once user Facebook Like or +1 your page
Love It Developer Profile
94 plugins · 23.5M total installs
How We Detect Love It
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/love-it/includes/js/love-it.js/wp-content/plugins/love-it/includes/js/love-it.jsHTML / DOM Fingerprints
most-lovedloved-itemdata-loveddata-idlove_it_vars