
WP likes Security & Risk Analysis
wordpress.org/plugins/wp-likesWP Likes lets your blog visitors 'like' your posts on the go.
Is WP likes Safe to Use in 2026?
Use With Caution
Score 63/100WP likes has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'wp-likes' v3.1.1 plugin exhibits a mixed security posture. While it presents a small attack surface with only one entry point (a shortcode) and no exposed AJAX or REST API endpoints without authorization, there are significant concerns within its code. The presence of `create_function`, a deprecated and often insecure PHP function, is a red flag. Furthermore, a substantial 37% of SQL queries are not using prepared statements, increasing the risk of SQL injection vulnerabilities. Critically, none of the 18 identified output points are properly escaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially when combined with the lack of nonce and capability checks.
Key Concerns
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- 1 output points are not properly escaped
- Missing nonce checks
- Missing capability checks
- Use of dangerous function create_function
- SQL queries not using prepared statements (37%)
- Unpatched CVE
WP likes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP likes <= 3.1.1 - Cross-Site Request Forgery to Cross-Site Scripting
WP likes Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
WP likes Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
WP likes Maintenance & Trust
Maintenance Signals
Community Trust
WP likes Alternatives
WP Voting Contest Lite
wp-voting-contest
Let users cast votes on your images/photos.
Tribulant Gallery Voting
gallery-voting
Let users cast votes/likes on your WordPress gallery images/photos.
Upvotr
upvotr
A WordPress plugin to allow simple upvoting of post objects by a user.
kk Star Ratings – Rate Post & Collect User Feedbacks
kk-star-ratings
kk Star Ratings allows blog visitors to involve and interact more effectively with your website by rating posts.
WP ULike – Like & Dislike Buttons for Engagement and Feedback
wp-ulike
Voting buttons that let your visitors give instant feedback. See what your audience loves with no registration, no friction, just one click.
WP likes Developer Profile
1 plugin · 100 total installs
How We Detect WP likes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-likes/wp_likes_post.css/wp-content/plugins/wp-likes/wp_likes_admin.css/wp-content/plugins/wp-likes/wp_likes_scripts.jswp-likes/wp_likes_post.css?ver=wp-likes/wp_likes_admin.css?ver=wp-likes/wp_likes_scripts.js?ver=HTML / DOM Fingerprints
wp_likes_sidebarname="wp_likes_post"name="wp_likes_reset"name="wp_likes_css"name="wp_likes_showOnPages"name="wp_likes_showOnMainPage"name="wp_likes_WPSuperCache"+5 morewp_likes_settings[wp_likes]