
WP Love It Security & Risk Analysis
wordpress.org/plugins/wp-love-itAdd a simple "Love It" button to post
Is WP Love It Safe to Use in 2026?
Generally Safe
Score 85/100WP Love It has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wp-love-it' v1.0.0 plugin exhibits a mixed security posture. While it boasts no known vulnerabilities in its history and avoids dangerous functions, SQL injections, and external HTTP requests, several critical security concerns are present in its static analysis. The plugin exposes two AJAX handlers, both of which lack authentication checks, presenting a significant attack surface for unauthenticated users. Furthermore, none of the identified output points are properly escaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks on AJAX handlers and capability checks exacerbates these risks, as it allows any user to trigger these potentially vulnerable actions without proper authorization or validation. The vulnerability history shows a clean slate, which is positive, but it does not mitigate the immediate dangers identified in the code itself. In conclusion, despite a lack of historical exploits, the current version of 'wp-love-it' has significant, unaddressed security flaws that require immediate attention to prevent exploitation.
Key Concerns
- Unprotected AJAX handlers
- Output escaping missing
- Missing nonce checks
- Missing capability checks
WP Love It Security Vulnerabilities
WP Love It Code Analysis
Output Escaping
WP Love It Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
WP Love It Maintenance & Trust
Maintenance Signals
Community Trust
WP Love It Alternatives
Managed posts rating ★ Like button
managed-posts-rating-like-button
Rating system for your WordPress site with a simple "like" button and advanced admin panel.
kk Star Ratings – Rate Post & Collect User Feedbacks
kk-star-ratings
kk Star Ratings allows blog visitors to involve and interact more effectively with your website by rating posts.
Rate My Post – Star Rating Plugin by FeedbackWP
rate-my-post
Add Star Rating to WordPress posts & pages, collect feedbacks from users and improve website SEO with Schema markup for Rich Snippets.
YASR – Yet Another Star Rating Plugin for WordPress
yet-another-stars-rating
Boost the way people interact with your site with an easy WordPress stars rating system! With schema.org rich snippets YASR will improve your SEO
Comments Like Dislike
comments-like-dislike
Like Dislike for WordPress Comments
WP Love It Developer Profile
4 plugins · 180 total installs
How We Detect WP Love It
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-love-it/css/love-it.css/wp-content/plugins/wp-love-it/js/js.cookie.js/wp-content/plugins/wp-love-it/js/love-it.js/wp-content/plugins/wp-love-it/js/js.cookie.js/wp-content/plugins/wp-love-it/js/love-it.js/wp-content/plugins/wp-love-it/js/love-it.js?ver=1.0.0HTML / DOM Fingerprints
pt-love-itlove-buttonlove-countdata-idloveit<div id="pt-love-it-" class="pt-love-it"><a class="love-button" data-id="