Simple Like Page Plugin – Fast & Privacy-Friendly Page Embeds Security & Risk Analysis

wordpress.org/plugins/simple-facebook-plugin

Embed Meta™ Page content without slowing down your site or loading third-party scripts before user interaction.

10K active installs v2.0.0 PHP 7.2+ WP 5.8+ Updated Mar 6, 2026
embedsfacebookperformanceprivacysocial
74
B · Generally Safe
CVEs total3
Unpatched1
Last CVEDec 31, 2025
Safety Verdict

Is Simple Like Page Plugin – Fast & Privacy-Friendly Page Embeds Safe to Use in 2026?

Mostly Safe

Score 74/100

Simple Like Page Plugin – Fast & Privacy-Friendly Page Embeds is generally safe to use. 3 past CVEs were resolved. Keep it updated.

3 known CVEs 1 unpatched Last CVE: Dec 31, 2025Updated 28d ago
Risk Assessment

The simple-facebook-plugin v2.0.0 exhibits a mixed security posture. On the positive side, the static analysis shows good practices in handling SQL queries with prepared statements and a high percentage of properly escaped output, indicating an effort to prevent common web vulnerabilities. The plugin also demonstrates a limited attack surface with only one shortcode and no direct entry points for AJAX or REST API manipulation. However, the significant concern lies in its vulnerability history. The plugin has a total of 3 known CVEs, with one currently unpatched. The historical prevalence of Missing Authorization and Cross-site Scripting (XSS) vulnerabilities is a strong indicator of recurring security weaknesses. The absence of nonce checks in the static analysis, coupled with the past XSS issues, raises questions about input validation and protection against CSRF or other client-side attacks, even with a seemingly small attack surface.

Key Concerns

  • Unpatched CVEs
  • Past XSS vulnerabilities
  • Past Missing Authorization vulnerabilities
  • No nonce checks
Vulnerabilities
3

Simple Like Page Plugin – Fast & Privacy-Friendly Page Embeds Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2024
2024
1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-63022medium · 5.3Missing Authorization

Simple Like Page <= 1.5.3 - Missing Authorization

Dec 31, 2025Unpatched
CVE-2024-3583medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simple Like Page Plugin <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

May 29, 2024 Patched in 1.5.3 (2d)
CVE-2023-4888medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simple Like Page Plugin <= 1.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Nov 6, 2023 Patched in 1.5.2 (78d)
Code Analysis
Analyzed Mar 16, 2026

Simple Like Page Plugin – Fast & Privacy-Friendly Page Embeds Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
54 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped55 total outputs
Attack Surface

Simple Like Page Plugin – Fast & Privacy-Friendly Page Embeds Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[sfp-page-plugin] simple-facebook-plugin.php:113
WordPress Hooks 9
actionadmin_menusimple-facebook-plugin.php:79
actionadmin_noticessimple-facebook-plugin.php:80
actionwidgets_initsimple-facebook-plugin.php:81
actionadmin_initsimple-facebook-plugin.php:83
actionadmin_initsimple-facebook-plugin.php:84
actionadmin_initsimple-facebook-plugin.php:85
actionadmin_enqueue_scriptssimple-facebook-plugin.php:86
actioninitsimple-facebook-plugin.php:87
filterplugin_row_metasimple-facebook-plugin.php:91
Maintenance & Trust

Simple Like Page Plugin – Fast & Privacy-Friendly Page Embeds Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 6, 2026
PHP min version7.2
Downloads339K

Community Trust

Rating86/100
Number of ratings24
Active installs10K
Developer Profile

Simple Like Page Plugin – Fast & Privacy-Friendly Page Embeds Developer Profile

topdevs.net

1 plugin · 10K total installs

70
trust score
Avg Security Score
74/100
Avg Patch Time
40 days
View full developer profile
Detection Fingerprints

How We Detect Simple Like Page Plugin – Fast & Privacy-Friendly Page Embeds

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-facebook-plugin/lib/css/sfp-admin-style.css
Version Parameters
simple-facebook-plugin/lib/css/sfp-admin-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
sfp-color-field
HTML Comments
Thanks for using our <strong>Simple Like Page Plugin</strong>! We have some other great WordPress plugins <a href="http://codecanyon.net/user/topdevs/portfolio?ref=topdevs">View Portfolio</a> |
JS Globals
initSfpColors
Shortcode Output
[sfp-page-plugin]
FAQ

Frequently Asked Questions about Simple Like Page Plugin – Fast & Privacy-Friendly Page Embeds