
WP LikeJS Security & Risk Analysis
wordpress.org/plugins/wp-likejsWP LikeJS includes an eyecatching Facebook Like Box on your website. You'll get more Fans with LikeJS than with an usual Like Button and it locks …
Is WP LikeJS Safe to Use in 2026?
Generally Safe
Score 100/100WP LikeJS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-likejs plugin, version 1.0.1, presents a mixed security picture. On the positive side, it demonstrates adherence to secure coding practices by completely avoiding SQL injection vulnerabilities through the exclusive use of prepared statements. Furthermore, its attack surface appears to be minimal, with no registered AJAX handlers, REST API routes, shortcodes, or cron events, indicating a limited number of potential entry points for attackers. The absence of known CVEs and historical vulnerabilities is also a strong indicator of a stable and well-maintained codebase. However, a significant concern is the complete lack of output escaping. With 100% of outputs unescaped, the plugin is highly susceptible to Cross-Site Scripting (XSS) attacks, which could lead to unauthorized actions, session hijacking, or data theft. Additionally, the absence of nonce checks and capability checks, even with a seemingly small attack surface, leaves the door open for potential unauthorized operations if any entry points were to be discovered or introduced in future versions. The taint analysis also flagged flows with unsanitized paths, which, while not resulting in critical or high severity, warrants attention as it indicates potential for path traversal or other file-related vulnerabilities if not carefully managed.
Key Concerns
- All outputs are unescaped
- No nonce checks
- No capability checks
- Taint flows with unsanitized paths
WP LikeJS Security Vulnerabilities
WP LikeJS Code Analysis
Output Escaping
Data Flow Analysis
WP LikeJS Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP LikeJS Maintenance & Trust
Maintenance Signals
Community Trust
WP LikeJS Alternatives
Mongoose Page Plugin
facebook-page-feed-graph-api
The most popular way to display the Facebook Page Plugin on your WordPress website. Easy implementation using a shortcode or widget.
Easy Social Like Box – Popup – Sidebar Widget
cardoza-facebook-like-box
WP Facebook Like Box Plugin enables you to display the facebook page likes in sidebar widget or popup. Display like button for the posts.
Social Like Box and Page by WpDevArt
like-box
WordPress Facebook Like box plugin will help you to display like box on your website, just add our plugin widget to your sidebar and use it.
Easy Social Box / Page Plugin
easy-facebook-like-box
Easy Social box display facebook like box. it enable Facebook Page owners to attract and gain Likes from their own website.
Aspexi Social Media Slider
aspexi-facebook-like-box
Plugin adds fancy Facebook Page Plugin (formerly Like Box) slider (slide on hover).
WP LikeJS Developer Profile
1 plugin · 20 total installs
How We Detect WP LikeJS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-likejs/wp-likejs.css/wp-content/plugins/wp-likejs/img/close.png/wp-content/plugins/wp-likejs/img/relikejsbox.jpgHTML / DOM Fingerprints
fixed<!-- LIKEJS HTML -->id="likejsbox"id="relikejsbox"onClick="closeLikeJSBox()"onClick="reLikeJSBox()"closeLikeJSBoxreLikeJSBoxsetCookiegetCookie