Responsive Like Box, Like Box Widget Security & Risk Analysis

wordpress.org/plugins/responsive-facebook-like-box

Responsible Facebook Like Box plugin helps you create a simple widgets, shortcode and gutenberg block for facebook like box in WordPress.

1K active installs v3.1.0 PHP + WP 3.0+ Updated Sep 27, 2024
facebook-like-boxfacebook-like-box-blockfacebook-like-box-widgetgutenberg-blockwordpress-facebook-like-box
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Responsive Like Box, Like Box Widget Safe to Use in 2026?

Generally Safe

Score 92/100

Responsive Like Box, Like Box Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "responsive-facebook-like-box" plugin v3.1.0 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and a lack of recorded vulnerabilities in its history are all positive indicators. The plugin also demonstrates a limited attack surface, with only one shortcode entry point and no unprotected AJAX handlers or REST API routes found.

However, there are notable areas for improvement. The most significant concern is the extremely low percentage of properly escaped output (19%). This suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied or dynamically generated content may not be properly sanitized before being displayed to users. The absence of nonce checks and capability checks on the identified entry point, while seemingly mitigated by the low attack surface, is still a potential weakness that could be exploited if the attack surface were to expand or if an XSS vulnerability allowed for the injection of malicious code.

In conclusion, while the plugin benefits from a clean vulnerability history and a small attack surface, the pervasive lack of output escaping presents a substantial risk. This weakness outweighs the positive aspects and should be a primary focus for remediation. Addressing the output escaping issues is crucial for improving the plugin's overall security.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Responsive Like Box, Like Box Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Responsive Like Box, Like Box Widget Release Timeline

v2.2.1
v2.1.0
v1.0
Code Analysis
Analyzed Mar 16, 2026

Responsive Like Box, Like Box Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

19% escaped31 total outputs
Attack Surface

Responsive Like Box, Like Box Widget Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[responsive-facebook-like-box] inc\shortcode.php:9
WordPress Hooks 2
actionwidgets_initfacebook.php:122
actioninitfacebook.php:140
Maintenance & Trust

Responsive Like Box, Like Box Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 27, 2024
PHP min version
Downloads54K

Community Trust

Rating62/100
Number of ratings14
Active installs1K
Developer Profile

Responsive Like Box, Like Box Widget Developer Profile

Prem Tiwari

10 plugins · 12K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
238 days
View full developer profile
Detection Fingerprints

How We Detect Responsive Like Box, Like Box Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/responsive-facebook-like-box/gutenberg-facebook-like-box.transpiled.js

HTML / DOM Fingerprints

CSS Classes
fb-like-box
Data Attributes
data-hrefdata-colorschemedata-show-facesdata-streamdata-headerdata-border-color
Shortcode Output
<div class="fb-like-box" data-href="" data-show-faces="" data-stream="" data-colorscheme="
FAQ

Frequently Asked Questions about Responsive Like Box, Like Box Widget