Lyket like buttons Security & Risk Analysis

wordpress.org/plugins/lyket-like-buttons

Lyket like buttons lets you add beautiful clap, like and dislike buttons on your Wordpress website.

20 active installs v1.2 PHP + WP 1.0+ Updated Aug 19, 2021
clap-buttonlike-buttonlike-dislike-button
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lyket like buttons Safe to Use in 2026?

Generally Safe

Score 85/100

Lyket like buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The lyket-like-buttons plugin version 1.2 exhibits a strong security posture in several key areas. The absence of any identified CVEs, combined with no known unpatched vulnerabilities, suggests a history of responsible security practices or a lack of targeted attacks. Furthermore, the static analysis reveals no critical code signals such as dangerous functions, file operations, or external HTTP requests. The SQL queries are also securely handled using prepared statements. However, a significant concern arises from the extremely low percentage of properly escaped output (1%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data displayed on the frontend might not be properly sanitized, allowing attackers to inject malicious scripts. The lack of nonce and capability checks, while not directly exposed through the limited attack surface identified, points to a potential weakness if new entry points were ever introduced.

Key Concerns

  • Poor output escaping
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Lyket like buttons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Lyket like buttons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
86
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

1% escaped87 total outputs
Attack Surface

Lyket like buttons Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionrender_lyket_formadmin\form\render.php:6
actionregister_user_settingsadmin\initializers\api.php:2
actionregister_buttons_settingsadmin\initializers\buttons.php:2
actionadmin_enqueue_scriptsadmin\main.php:9
actionadmin_enqueue_scriptsadmin\main.php:17
actionadmin_menuadmin\main.php:36
actionadmin_initadmin\main.php:54
filterthe_contentapp\main.php:2
filterthe_excerptapp\main.php:3
actionwp_headscripts\load_lyket.php:15
actionadmin_headscripts\load_lyket.php:16
Maintenance & Trust

Lyket like buttons Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedAug 19, 2021
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs20
Developer Profile

Lyket like buttons Developer Profile

Lyket

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lyket like buttons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lyket-like-buttons/admin/styles/lyket_admin.css/wp-content/plugins/lyket-like-buttons/admin/scripts/wp_color_picker_alpha.js/wp-content/plugins/lyket-like-buttons/admin/scripts/wp_color_picker.js/wp-content/plugins/lyket-like-buttons/admin/scripts/lyket_interactive_preview.js/wp-content/plugins/lyket-like-buttons/lyket.js
Script Paths
/wp-content/plugins/lyket-like-buttons/lyket.js
Version Parameters
lyket-like-buttons/style.css?ver=lyket-like-buttons/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
lyket-widget
Data Attributes
data-lyket-api-keydata-lyket-themedata-lyket-typedata-lyket-colordata-lyket-font-familydata-lyket-font-weight+5 more
JS Globals
Lyket
Shortcode Output
[lyket_button]
FAQ

Frequently Asked Questions about Lyket like buttons