
Sina Weibo Like Button 新浪微博赞按钮 Security & Risk Analysis
wordpress.org/plugins/weibo-likeAdds Sina Weibo Like button on your site. A must-have plugin if your site visitors are mainly from China.
Is Sina Weibo Like Button 新浪微博赞按钮 Safe to Use in 2026?
Generally Safe
Score 100/100Sina Weibo Like Button 新浪微博赞按钮 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "weibo-like" plugin version 1.0.3 exhibits a strong initial security posture based on the provided static analysis. It has a remarkably small attack surface, with zero identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code signals are largely positive, indicating no dangerous functions used, all SQL queries employing prepared statements, and no file operations or external HTTP requests. This suggests a well-contained and securely coded plugin from the outset.
However, there are notable areas for concern. The static analysis reveals that only 50% of output is properly escaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities if the unescaped output is rendered in user-facing contexts. The complete absence of nonce checks and capability checks on any potential, albeit currently non-existent, entry points is also a significant omission. While the attack surface is zero, if this were to change in future versions or if there are hidden entry points not detected, the lack of these fundamental security measures would be a critical weakness.
The plugin's vulnerability history is clean, with zero known CVEs. This is a strong indicator that the plugin has historically been secure or that any past issues have been promptly addressed and patched. The lack of recorded common vulnerability types further reinforces this positive trend. Overall, while the current version appears robust due to its minimal attack surface and clean history, the unescaped output and complete lack of built-in authentication and authorization mechanisms for potential entry points represent the primary risks.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
Sina Weibo Like Button 新浪微博赞按钮 Security Vulnerabilities
Sina Weibo Like Button 新浪微博赞按钮 Code Analysis
Output Escaping
Sina Weibo Like Button 新浪微博赞按钮 Attack Surface
WordPress Hooks 16
Maintenance & Trust
Sina Weibo Like Button 新浪微博赞按钮 Maintenance & Trust
Maintenance Signals
Community Trust
Sina Weibo Like Button 新浪微博赞按钮 Alternatives
Mongoose Page Plugin
facebook-page-feed-graph-api
The most popular way to display the Facebook Page Plugin on your WordPress website. Easy implementation using a shortcode or widget.
Social Like Box and Page by WpDevArt
like-box
WordPress Facebook Like box plugin will help you to display like box on your website, just add our plugin widget to your sidebar and use it.
Posts Like Dislike
posts-like-dislike
Like Dislike for WordPress Posts | WordPress Page | Custom Post Types
All-in-one Like Widget
all-in-one-facebook-like-widget
All-in-one Like Widget. Lets you quickly add a Like Button, activity stream and/or a Fanbox to your WordPress site for your Facebook fanpage (as a wid …
Fan Page Widget by ThemeNcode
facebook-fan-page-widget
An widget that will display Facebook Fan page like box. Uses latest API of Facebook (v 16.0)
Sina Weibo Like Button 新浪微博赞按钮 Developer Profile
8 plugins · 4K total installs
How We Detect Sina Weibo Like Button 新浪微博赞按钮
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/weibo-like/weibo-like.css/wp-content/plugins/weibo-like/weibo-like.js/wp-content/plugins/weibo-like/weibo-like.jsweibo-like.css?ver=weibo-like.js?ver=HTML / DOM Fingerprints
weibo-like-btnweibo-like-iconweibo-like-count<!-- Sina Weibo Like Button --><!-- Weibo Like Button -->data-weibo-idweibo_like_config[weibo_like]