
Post Reaction – Add Like or Emoji Reactions to Posts Security & Risk Analysis
wordpress.org/plugins/post-reactionAdd Facebook Reaction interface in WordPress Posts and Count them (likes, loves, cares, custom react)
Is Post Reaction – Add Like or Emoji Reactions to Posts Safe to Use in 2026?
Generally Safe
Score 100/100Post Reaction – Add Like or Emoji Reactions to Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "post-reaction" plugin v1.0.0 exhibits a generally good security posture, with no known vulnerabilities in its history and strong coding practices evident in the static analysis. Notably, all output is properly escaped, and there are no file operations or external HTTP requests, minimizing common attack vectors. The use of prepared statements for the majority of SQL queries is also a positive indicator of secure data handling.
However, the taint analysis reveals two flows with unsanitized paths, flagged as high severity. While the plugin has an "attack surface" with two AJAX handlers, the static analysis indicates that these are protected and there are no unprotected entry points. The presence of a single nonce check, alongside the absence of capability checks for the AJAX handlers, could be a potential concern, especially if the taint analysis's "unsanitized paths" relate to these handlers. The lack of historical vulnerabilities is a good sign, but the high-severity taint flows are a critical point of attention that requires further investigation.
In conclusion, while the plugin demonstrates a strong foundation with secure output handling and SQL practices, the identified high-severity taint flows are a significant concern. The limited vulnerability history suggests past robustness, but these new findings necessitate immediate attention to ensure the plugin's continued security and to prevent potential exploitation through the identified unsanitized paths.
Key Concerns
- High severity taint flows with unsanitized paths
- AJAX handlers lack capability checks
Post Reaction – Add Like or Emoji Reactions to Posts Security Vulnerabilities
Post Reaction – Add Like or Emoji Reactions to Posts Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Post Reaction – Add Like or Emoji Reactions to Posts Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
Post Reaction – Add Like or Emoji Reactions to Posts Maintenance & Trust
Maintenance Signals
Community Trust
Post Reaction – Add Like or Emoji Reactions to Posts Alternatives
Booster Extension
booster-extension
Booster Extension is a free WordPress plugin that supercharges your site with awesome powerful features. There’re numerous plugins in the official Wor …
I Recommend This – Love/Like Button for WordPress Posts
i-recommend-this
Enable your visitors to easily like or recommend your posts with a single click, enhancing engagement without the need for comments.
WPAC Social Tools – Like, React & Share
wpac-like-system
The Most Simple WordPress Post Like, Dislike & Reaction System with Social Sharing.
Love Me
love-me
Display a very simple and customisable like button for your posts or any custom post type.
Instant Emoji Reactions
instant-emoji-reactions
Add emoji reactions to posts and custom post types on your WordPress site, enabling both logged-in and guest users to express their feelings.
Post Reaction – Add Like or Emoji Reactions to Posts Developer Profile
120 plugins · 738K total installs
How We Detect Post Reaction – Add Like or Emoji Reactions to Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-reaction/dist/public.css/wp-content/plugins/post-reaction/dist/public.js/wp-content/plugins/post-reaction/dist/settings.css/wp-content/plugins/post-reaction/dist/settings.js/wp-content/plugins/post-reaction/dist/public.js/wp-content/plugins/post-reaction/dist/settings.jspost-reaction/dist/public.css?ver=post-reaction/dist/public.js?ver=post-reaction/dist/settings.css?ver=post-reaction/dist/settings.js?ver=HTML / DOM Fingerprints
post-reactions-listreacted_toprc_react_icondata-iddata-react-typepostReactScript/wp-json/cpr/v1/settings