
Like This Security & Risk Analysis
wordpress.org/plugins/roses-like-thisA simple 'I like this' plugin inspired by the facebook 'like' functionality.
Is Like This Safe to Use in 2026?
Generally Safe
Score 85/100Like This has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "roses-like-this" plugin version 1.6.2 exhibits a concerning security posture primarily due to its unprotected AJAX handlers. With two identified AJAX entry points and neither implementing any form of authentication or authorization checks, these handlers represent a significant attack surface. Any attacker could potentially trigger these functions without prior verification, leading to unintended actions or data manipulation within the WordPress environment. While the plugin demonstrates good practice by utilizing prepared statements for its single SQL query and has no recorded vulnerabilities or critical taint flows, the absence of security checks on its primary entry points overshadows these strengths. The presence of the `create_function` is also a notable concern, as it's considered a deprecated and potentially insecure function that can be exploited if not handled with extreme care, though no specific exploitable taint flow was identified from it in this analysis. The extremely low percentage of properly escaped output (7%) is another critical weakness, suggesting a high probability of Cross-Site Scripting (XSS) vulnerabilities being present. Overall, the plugin's lack of basic security hygiene on its AJAX handlers and pervasive unescaped output creates a substantial risk for users, despite its clean vulnerability history.
Key Concerns
- AJAX handlers without authentication checks
- Low output escaping percentage
- Use of dangerous 'create_function'
- AJAX handlers without capability checks
- AJAX handlers without nonce checks
Like This Security Vulnerabilities
Like This Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Like This Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Maintenance & Trust
Like This Maintenance & Trust
Maintenance Signals
Community Trust
Like This Alternatives
My Favorites
my-favorites
Save user's favorite posts and list them.
Solid Post Likes
solid-post-likes
A like button for all post types. Solid and simple.
Lotos Likes
lotos-likes
Add "like" functionality to your posts and pages
Bainternet User Ranks
bainternet-user-ranks
Create and display user rank titles based on there post count, comment count or both.
Simple custom post likes
simple-custom-post-likes
Appends a custom likes box that allows a user to like any post type from the front end.
Like This Developer Profile
1 plugin · 2K total installs
How We Detect Like This
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/roses-like-this/likesScript.js/wp-content/plugins/roses-like-this/likesScript.jsroses-like-this/likesScript.js?ver=HTML / DOM Fingerprints
likeThisdata-post-idlike_this_ajax_object/wp-json/wp/v2/posts