
Add Links to Pages Security & Risk Analysis
wordpress.org/plugins/add-links-to-pagesAdd Links to Pages allows you to add page specific links and have tim displayed through a widget.
Is Add Links to Pages Safe to Use in 2026?
Generally Safe
Score 85/100Add Links to Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "add-links-to-pages" v0.2 plugin exhibits a concerning security posture primarily due to significant weaknesses in output handling and the presence of a dangerous function. While the plugin has a clean vulnerability history and demonstrates good practices in SQL query preparation and avoiding external requests, the lack of any output escaping across all identified output points is a critical flaw. This means any user-supplied data, if processed and outputted by the plugin, could be vulnerable to Cross-Site Scripting (XSS) attacks.
The static analysis also flagged the use of the `create_function` dangerous function, which is generally discouraged due to security risks, although its specific impact here is not detailed in the provided data. The complete absence of any identified attack surface (AJAX, REST API, shortcodes, cron events) might suggest limited functionality, but it's unusual for a plugin to have zero entry points. This could either indicate a very specialized, internal-use plugin or a potential misconfiguration in the static analysis process itself.
Given the lack of past vulnerabilities and the positive SQL practices, the plugin's developers appear to be following some good security principles. However, the critical oversight in output escaping and the use of a dangerous function present immediate and significant risks that must be addressed. The overall security posture is weak due to these critical flaws, despite the absence of known CVEs.
Key Concerns
- 0% properly escaped output
- Use of dangerous function 'create_function'
Add Links to Pages Security Vulnerabilities
Add Links to Pages Code Analysis
Dangerous Functions Found
Output Escaping
Add Links to Pages Attack Surface
WordPress Hooks 3
Maintenance & Trust
Add Links to Pages Maintenance & Trust
Maintenance Signals
Community Trust
Add Links to Pages Alternatives
Sitemap by BestWebSoft – WordPress XML Site Map Page Generator Plugin
google-sitemap-plugin
Generate and add XML sitemap to WordPress website. Help search engines index your blog.
Bulk Page Creator
bulk-page-creator
Allows you to create multiple pages in a batch/bulk manner saving time when initially setting up your WordPress site
Disable Author Archives
disable-author-archives
Disable Author Archives completely removes author archives and makes the web server return status code 404 ('Not Found') instead.
PDF & Print by BestWebSoft – WordPress Posts and Pages PDF Generator Plugin
pdf-print
Generate PDF files and print WordPress posts/pages. Customize document header/footer styles and appearance.
Admin Collapse Subpages
admin-collapse-subpages
Using this plugin one can easily collapse/expand pages with children and grand children.
Add Links to Pages Developer Profile
5 plugins · 900 total installs
How We Detect Add Links to Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-links-to-pages/img/delete.png/wp-content/plugins/add-links-to-pages/js/altp.jsHTML / DOM Fingerprints
altp_removealtp_link_containeraltp_widgetid="altp_url"id="altp_window"id="altp_name"id="altp_desc"id="altp_links_html"id="altp_links"addRemoveDiv();