
Simple custom post likes Security & Risk Analysis
wordpress.org/plugins/simple-custom-post-likesAppends a custom likes box that allows a user to like any post type from the front end.
Is Simple custom post likes Safe to Use in 2026?
Generally Safe
Score 85/100Simple custom post likes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "simple-custom-post-likes" v1.0 exhibits a concerning security posture due to multiple unprotected entry points and a lack of robust security practices. The static analysis reveals two AJAX handlers, both lacking authentication checks, creating a significant attack surface. This directly exposes functionality to unauthenticated users, potentially allowing for unauthorized actions. Furthermore, the analysis indicates that 100% of output escaping is improperly implemented, meaning user-supplied data or plugin-generated content could be vulnerable to cross-site scripting (XSS) attacks. While the vulnerability history is clean, this lack of past issues does not negate the identified code-level risks. The presence of raw SQL queries without prepared statements also poses a risk of SQL injection, especially when combined with unsanitized input.
Key Concerns
- Unprotected AJAX handlers
- No output escaping
- SQL queries without prepared statements
- No nonce checks on AJAX
- No capability checks
Simple custom post likes Security Vulnerabilities
Simple custom post likes Release Timeline
Simple custom post likes Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Simple custom post likes Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
Simple custom post likes Maintenance & Trust
Maintenance Signals
Community Trust
Simple custom post likes Alternatives
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
Featured Posts and Custom Posts
featured-posts-and-custom-posts
Allows the user to feature posts and custom posts. When a post is featured it gets the post metta _jsFeaturedPost.
Post Type Spotlight
post-type-spotlight
x-release-please-start-version Stable tag: 3.0.3 x-release-please-end License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.
WP Featured News – Custom Posts Listing Elements
wp-featured-news-custom-posts-listing-elements
WP Featured News plugin allows you to display your posts anywhere of your web-pages with 10 powerful and creatively designed post blocks.
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Simple custom post likes Developer Profile
2 plugins · 20 total installs
How We Detect Simple custom post likes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-custom-post-likes/assets/css/style.cssHTML / DOM Fingerprints
user_favouriteid="user_favourite"type="button"ajaxurl