
Admin Links Plus Security & Risk Analysis
wordpress.org/plugins/admin-links-plus-alp-widgetNote that this plugin is largely obsolete with the new admin ribbon in WP3.
Is Admin Links Plus Safe to Use in 2026?
Generally Safe
Score 85/100Admin Links Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'admin-links-plus-alp-widget' v1.3.0 exhibits a mixed security posture. On the positive side, the absence of known CVEs and the use of prepared statements for all SQL queries are strong indicators of good development practices regarding external threats and data integrity. The plugin also demonstrates a very small attack surface, with no apparent AJAX handlers, REST API routes, shortcodes, or cron events, significantly reducing the number of potential entry points for attackers. However, the static analysis reveals a critical concern: 100% of output is not properly escaped. This means that any data displayed by the plugin, if it originates from user input or external sources, is vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, while the taint analysis shows no critical or high-severity unsanitized paths, it did identify 3 flows with unsanitized paths, indicating a potential for subtle injection vulnerabilities if these paths are ever exposed or interact with user-controlled data.
Key Concerns
- All output is unescaped
- 3 flows with unsanitized paths
- No nonce checks
- No capability checks
Admin Links Plus Security Vulnerabilities
Admin Links Plus Release Timeline
Admin Links Plus Code Analysis
Output Escaping
Data Flow Analysis
Admin Links Plus Attack Surface
WordPress Hooks 1
Maintenance & Trust
Admin Links Plus Maintenance & Trust
Maintenance Signals
Community Trust
Admin Links Plus Alternatives
Admin Links Widget
admin-links-sidebar-widget
This plugin provides a widget which can contain links to pages in the administration panel in one of your sidebars. These links are only visible to t …
Dashboard quick links widget
dashboard-quick-link-widget
A lightweight plugin to allows admins to create a admin dashboard widget with frequently accessed links for quick access.
QuickLinks Manager by Press.Zone
quicklinks-manager
QuickLinks Manager by Press.Zone lets you create and manage custom quick links in the WordPress dashboard for easier navigation.
DashLinx – Admin Dashboard Links Widget
dashlinx
Admin dashboard links.
Error Log Monitor
error-log-monitor
Adds a Dashboard widget that displays the latest messages from your PHP error log. It can also send logged errors to email.
Admin Links Plus Developer Profile
2 plugins · 20 total installs
How We Detect Admin Links Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
inputforgetmenotsubmitcheckbox<!-- -->id="alp_loginform"name="loginform"id="user_login"name="log"id="user_pass"name="pwd"+26 more