
Recommend Security & Risk Analysis
wordpress.org/plugins/recommendRecommend allows you to add a like user action to your content. Unlike social sharing or commenting, the like action is simple and intuitive.
Is Recommend Safe to Use in 2026?
Generally Safe
Score 100/100Recommend has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "recommend" v0.6.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerabilities. The absence of file operations and external HTTP requests also reduces the attack surface. However, significant concerns arise from the static analysis. The presence of four unprotected AJAX handlers represents a substantial risk, as these entry points could be exploited by unauthenticated users. Furthermore, a lack of nonce and capability checks across the board on these AJAX handlers exacerbates this vulnerability, potentially allowing for unauthorized actions. While taint analysis and SQL practices are commendable, the unprotected AJAX handlers and general lack of permission checks are critical weaknesses that overshadow the plugin's strengths.
Key Concerns
- Unprotected AJAX handlers (4)
- Missing nonce checks on AJAX handlers
- Missing capability checks on AJAX handlers
- Output escaping (37% unescaped)
Recommend Security Vulnerabilities
Recommend Code Analysis
Output Escaping
Recommend Attack Surface
AJAX Handlers 4
Shortcodes 2
WordPress Hooks 13
Maintenance & Trust
Recommend Maintenance & Trust
Maintenance Signals
Community Trust
Recommend Alternatives
I Recommend This – Love/Like Button for WordPress Posts
i-recommend-this
Enable your visitors to easily like or recommend your posts with a single click, enhancing engagement without the need for comments.
Lotos Likes
lotos-likes
Add "like" functionality to your posts and pages
Like Post Block
like-post-block
Add a button to like any post type.
Applause/Like/Upvote Button
applause
Add an applause/like/upvote button to your content.
Post Like Manager
pl-manager
A smooth ajax-based like/dislike functionality for wordpress posts, pages, Custom post types..
Recommend Developer Profile
1 plugin · 10 total installs
How We Detect Recommend
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/recommend/assets/css/recommend.css/wp-content/plugins/recommend/assets/js/like-action.jsassets/js/like-action.jswp-recommend-csswp-recommend-jsHTML / DOM Fingerprints
recommend-likesrecommend-likes-iconrecommend-likes-countrecommend-likes-labellikeddata-post-idwp_recommend_ajax_url<button class="recommend-likes<p><button class="recommend-likes