
Simple custom post likes Security & Risk Analysis
wordpress.org/plugins/simple-custom-post-likesAppends a custom likes box that allows a user to like any post type from the front end.
Is Simple custom post likes Safe to Use in 2026?
Generally Safe
Score 85/100Simple custom post likes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "simple-custom-post-likes" v1.0 exhibits a concerning security posture due to multiple unprotected entry points and a lack of robust security practices. The static analysis reveals two AJAX handlers, both lacking authentication checks, creating a significant attack surface. This directly exposes functionality to unauthenticated users, potentially allowing for unauthorized actions. Furthermore, the analysis indicates that 100% of output escaping is improperly implemented, meaning user-supplied data or plugin-generated content could be vulnerable to cross-site scripting (XSS) attacks. While the vulnerability history is clean, this lack of past issues does not negate the identified code-level risks. The presence of raw SQL queries without prepared statements also poses a risk of SQL injection, especially when combined with unsanitized input.
Key Concerns
- Unprotected AJAX handlers
- No output escaping
- SQL queries without prepared statements
- No nonce checks on AJAX
- No capability checks
Simple custom post likes Security Vulnerabilities
Simple custom post likes Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Simple custom post likes Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
Simple custom post likes Maintenance & Trust
Maintenance Signals
Community Trust
Simple custom post likes Alternatives
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
Featured Posts and Custom Posts
featured-posts-and-custom-posts
Allows the user to feature posts and custom posts. When a post is featured it gets the post metta _jsFeaturedPost.
Post Type Spotlight
post-type-spotlight
x-release-please-start-version Stable tag: 3.0.3 x-release-please-end License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.
WP Featured News – Custom Posts Listing Elements
wp-featured-news-custom-posts-listing-elements
WP Featured News plugin allows you to display your posts anywhere of your web-pages with 10 powerful and creatively designed post blocks.
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Simple custom post likes Developer Profile
2 plugins · 20 total installs
How We Detect Simple custom post likes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-custom-post-likes/assets/css/style.cssHTML / DOM Fingerprints
user_favouriteid="user_favourite"type="button"ajaxurl