
My Favorites Security & Risk Analysis
wordpress.org/plugins/my-favoritesSave user's favorite posts and list them.
Is My Favorites Safe to Use in 2026?
Generally Safe
Score 99/100My Favorites has a strong security track record. Known vulnerabilities have been patched promptly.
The "my-favorites" plugin v1.4.4 presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce checks for its AJAX handlers. The absence of shortcodes, cron events, and REST API routes, along with a small, protected attack surface, are also strengths. However, the presence of a dangerous `create_function` call is a significant concern, as it can be a vector for code injection if not handled with extreme caution and sanitization. Furthermore, only 40% of output is properly escaped, indicating a potential risk for Cross-Site Scripting (XSS) vulnerabilities, which aligns with its vulnerability history.
Key Concerns
- Dangerous function detected (create_function)
- Insufficient output escaping (40% proper)
- Previous vulnerabilities indicate XSS risks
My Favorites Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
My Favorites <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
My Favorites <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
My Favorites Code Analysis
Dangerous Functions Found
Output Escaping
My Favorites Attack Surface
AJAX Handlers 4
WordPress Hooks 5
Maintenance & Trust
My Favorites Maintenance & Trust
Maintenance Signals
Community Trust
My Favorites Alternatives
Favorites
favorites
Favorites for any post type. Easily add favoriting/liking, wishlists, or any other similar functionality using the developer-friendly API.
WP Favorite Posts Extended
wp-favorite-posts-extended
wp-favorite-posts, reading list, post list, post lists, lists Requires at least: 3.5 Tested up to: 4.0 Stable tag: 0.1 Based on plugin "WP Favor …
Keyring Reactions Importer
keyring-reactions-importer
A social reactions ( comments, like, favs, etc. ) importer.
Ally – Web Accessibility & Usability
pojo-accessibility
Ally: Make your site more inclusive by scanning for accessibility violations, fixing them easily, and adding a usability widget and accessibility stat …
Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)
auto-image-attributes-from-filename-with-bulk-updater
Automatically add Image Alt Text, Title, Caption and Description from Filename. Bulk update existing images. Great for Image SEO and Accessibility.
My Favorites Developer Profile
1 plugin · 1K total installs
How We Detect My Favorites
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/my-favorites/assets/select.css/wp-content/plugins/my-favorites/assets/select.js/wp-content/plugins/my-favorites/assets/list.css/wp-content/plugins/my-favorites/assets/list.js/wp-content/plugins/my-favorites/assets/select.js/wp-content/plugins/my-favorites/assets/list.jsmy-favorites/assets/select.css?ver=my-favorites/assets/select.js?ver=my-favorites/assets/list.css?ver=my-favorites/assets/list.js?ver=HTML / DOM Fingerprints
ccc-my-favorite-select-buttonccc-my-favorite-button-textccc-my-favorite-button-countccc-my-favorite-list-wrapperHow to use this ShortcodeCCC_My_Favorite InitializeInitial executionお気に入りの投稿をユーザーメタ(usermeta)に追加+5 moredata-post-iddata-actiondata-nonceCCC_MY_FAVORITE_UPDATECCC_MY_FAVORITE_GETCCC_MY_FAVORITE_LIST/wp-json/ccc_my_favorite-update-action/wp-json/ccc_my_favorite-get-action/wp-json/ccc_my_favorite-list-action[ccc_my_favorite_select_button[ccc_my_favorite_list_menu[ccc_my_favorite_list_results