WPAC Social Tools – Like, React & Share Security & Risk Analysis

wordpress.org/plugins/wpac-like-system

The Most Simple WordPress Post Like, Dislike & Reaction System with Social Sharing.

300 active installs v3.0.3 PHP 5.6.0+ WP 4.0+ Updated May 14, 2020
dislikelikepost-likereactionssocial-sharing
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPAC Social Tools – Like, React & Share Safe to Use in 2026?

Generally Safe

Score 85/100

WPAC Social Tools – Like, React & Share has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The wpac-like-system plugin v3.0.3 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and avoiding dangerous functions, file operations, and external HTTP requests. The vulnerability history is also clean, with no recorded CVEs, which is a strong indicator of a well-maintained and secure codebase. However, a significant concern arises from its attack surface. With 18 total entry points, a concerning 12 are unprotected AJAX handlers. This means a large portion of the plugin's functionality is accessible without any authentication or capability checks, creating a significant risk of unauthorized access and manipulation.

Key Concerns

  • Unprotected AJAX handlers
  • Lack of nonce checks on AJAX
  • Lack of capability checks on AJAX
Vulnerabilities
None known

WPAC Social Tools – Like, React & Share Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPAC Social Tools – Like, React & Share Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
20 prepared
Unescaped Output
29
108 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared20 total queries

Output Escaping

79% escaped137 total outputs
Data Flows
8 unsanitized

Data Flow Analysis

8 flows8 with unsanitized paths
wpac_dislike_btn_count_update (inc\ajax\dislike-btn-count.php:2)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
12 unprotected

WPAC Social Tools – Like, React & Share Attack Surface

Entry Points18
Unprotected12

AJAX Handlers 12

authwp_ajax_wpac_like_btn_ajax_actionwpac-like-system.php:65
noprivwp_ajax_wpac_like_btn_ajax_actionwpac-like-system.php:66
authwp_ajax_wpac_like_btn_count_updatewpac-like-system.php:69
noprivwp_ajax_wpac_like_btn_count_updatewpac-like-system.php:70
authwp_ajax_wpac_dislike_btn_ajax_actionwpac-like-system.php:74
noprivwp_ajax_wpac_dislike_btn_ajax_actionwpac-like-system.php:75
authwp_ajax_wpac_dislike_btn_count_updatewpac-like-system.php:78
noprivwp_ajax_wpac_dislike_btn_count_updatewpac-like-system.php:79
authwp_ajax_wpac_save_reaction_ajax_actionwpac-like-system.php:83
noprivwp_ajax_wpac_save_reaction_ajax_actionwpac-like-system.php:84
authwp_ajax_wpac_reaction_count_updatewpac-like-system.php:87
noprivwp_ajax_wpac_reaction_count_updatewpac-like-system.php:88

Shortcodes 6

[WPAC_LIKE_SYSTEM] inc\btns.php:133
[WPAC_LIKE_SYSTEM] inc\btns.php:136
[WPAC_LIKE_SYSTEM] inc\reactions.php:210
[WPAC_LIKE_SYSTEM] inc\reactions.php:213
[WPAC_LIKE_COUNT] inc\shortcodes.php:39
[WPAC_DISLIKE_COUNT] inc\shortcodes.php:77
WordPress Hooks 11
filterthe_contentinc\btns.php:135
filterthe_contentinc\reactions.php:212
actionwp_enqueue_scriptsinc\scripts.php:33
actionadmin_enqueue_scriptsinc\scripts.php:43
actionadmin_menuinc\setting-parts\menu-pages.php:11
actionadmin_menuinc\setting-parts\menu-pages.php:21
actionadmin_menuinc\setting-parts\menu-pages.php:31
actionadmin_menuinc\setting-parts\menu-pages.php:41
actionadmin_initinc\setting-parts\register-settings.php:309
actionwp_footerinc\static-functions.php:103
actionwidgets_initinc\widgets\wpac-popular-posts.php:193
Maintenance & Trust

WPAC Social Tools – Like, React & Share Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMay 14, 2020
PHP min version5.6.0
Downloads11K

Community Trust

Rating100/100
Number of ratings3
Active installs300
Developer Profile

WPAC Social Tools – Like, React & Share Developer Profile

Mian Shahzad Raza

4 plugins · 600 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPAC Social Tools – Like, React & Share

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpac-like-system/assets/css/front-end.css/wp-content/plugins/wpac-like-system/assets/font-awesome/css/all.min.css/wp-content/plugins/wpac-like-system/assets/font-awesome/css/v4-shims.min.css/wp-content/plugins/wpac-like-system/assets/js/ajax.js/wp-content/plugins/wpac-like-system/assets/js/frontend.js/wp-content/plugins/wpac-like-system/assets/css/main.css/wp-content/plugins/wpac-like-system/assets/js/main.js
Script Paths
assets/js/ajax.jsassets/js/frontend.jsassets/js/main.js
Version Parameters
wpac-like-system/assets/css/front-end.css?ver=wpac-like-system/assets/font-awesome/css/all.min.css?ver=wpac-like-system/assets/font-awesome/css/v4-shims.min.css?ver=wpac-like-system/assets/js/ajax.js?ver=wpac-like-system/assets/js/frontend.js?ver=wpac-like-system/assets/css/main.css?ver=wpac-like-system/assets/js/main.js?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
wpac-social-barwpac-share-iconwpac-like-btnwpac-dislike-btnwpac-react-btnwpac-reaction-menuwpac-like-countwpac-dislike-count
Data Attributes
data-post-iddata-user-id
JS Globals
wpac_ajax_urlwpac_like_btn_ajax_actionwpac_like_btn_count_updatewpac_dislike_btn_ajax_actionwpac_dislike_btn_count_updatewpac_save_reaction_ajax_action+1 more
REST Endpoints
/wp-json/wpac-like-system/v1/like/wp-json/wpac-like-system/v1/dislike/wp-json/wpac-like-system/v1/reaction
Shortcode Output
[wpac_like_button][wpac_dislike_button][wpac_reactions][wpac_popular_posts]
FAQ

Frequently Asked Questions about WPAC Social Tools – Like, React & Share