
Solid Post Likes Security & Risk Analysis
wordpress.org/plugins/solid-post-likesA like button for all post types. Solid and simple.
Is Solid Post Likes Safe to Use in 2026?
Generally Safe
Score 92/100Solid Post Likes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "solid-post-likes" plugin, version 1.0.8, exhibits a mixed security posture. While it demonstrates good practices in output escaping (96% properly escaped) and has no recorded vulnerability history or dangerous functions, several significant concerns warrant attention. The presence of four AJAX handlers without authentication checks creates a substantial attack surface, making them prime targets for unauthorized actions. Furthermore, the plugin's database interactions are concerning; 100% of its SQL queries lack prepared statements, which is a critical vulnerability that can lead to SQL injection attacks. Although taint analysis did not reveal critical or high severity issues, the two flows with unsanitized paths are still noteworthy and could potentially be exploited in conjunction with other weaknesses.
In conclusion, the plugin has strengths in output handling and a clean vulnerability history, which is positive. However, the unprotected AJAX endpoints and the complete lack of prepared statements for SQL queries represent serious security weaknesses. These, combined with the potential for unsanitized paths, create a considerable risk for sites using this plugin. Prioritizing the remediation of these issues is crucial to improving the plugin's overall security.
Key Concerns
- Unprotected AJAX handlers
- Raw SQL queries without prepared statements
- Flows with unsanitized paths
- Missing capability checks on AJAX handlers
Solid Post Likes Security Vulnerabilities
Solid Post Likes Release Timeline
Solid Post Likes Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Solid Post Likes Attack Surface
AJAX Handlers 4
Shortcodes 3
WordPress Hooks 12
Maintenance & Trust
Solid Post Likes Maintenance & Trust
Maintenance Signals
Community Trust
Solid Post Likes Alternatives
Easy Social Like Box – Popup – Sidebar Widget
cardoza-facebook-like-box
WP Facebook Like Box Plugin enables you to display the facebook page likes in sidebar widget or popup. Display like button for the posts.
Easy Social Box / Page Plugin
easy-facebook-like-box
Easy Social box display facebook like box. it enable Facebook Page owners to attract and gain Likes from their own website.
Like Button Rating ♥ LikeBtn
likebtn-like-button
Add Like button to posts, pages, comments, WooCommerce, BuddyPress, bbPress, UM, custom posts! Sort content by likes! Get instant stats and insights!
Profile Box Shortcode And Widget
facebook-likebox-widget-and-shortcode
A very easy and simple Facebook like box shortcode and widget plugin with mini profile, like Button, Share Button plugin For WordPress
All-in-one Like Widget
all-in-one-facebook-like-widget
All-in-one Like Widget. Lets you quickly add a Like Button, activity stream and/or a Fanbox to your WordPress site for your Facebook fanpage (as a wid …
Solid Post Likes Developer Profile
3 plugins · 510 total installs
How We Detect Solid Post Likes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/solid-post-likes/admin/css/admin-style.css/wp-content/plugins/solid-post-likes/public/css/style.css/wp-content/plugins/solid-post-likes/public/js/solid-post-likes.js/wp-content/plugins/solid-post-likes/public/js/solid-post-likes.jssolid-post-likes/public/css/style.css?ver=solid-post-likes/public/js/solid-post-likes.js?ver=solid-post-likes/admin/css/admin-style.css?ver=solid-post-likes/admin/js/admin-script.js?ver=HTML / DOM Fingerprints
oacs_spl_like_countoacs_spl_heart_iconsolid-post-likes-buttonspl-likes-iconspl-post-idspl-user-iddata-spl-post-iddata-spl-user-iddata-spl-countdata-spl-typesolid_post_likes_ajax_object[oacsspl][oacsspllist][oacs_spl_profile]