Advanced WPLink Security & Risk Analysis

wordpress.org/plugins/advanced-wplink

This Plugin adds several enhancements to the WP-Link Modal inside the TinyMCE and gives you the possibility to disable the wp inline link tool.

1K active installs v1.1.0 PHP + WP 4.5+ Updated Jun 21, 2018
inline-linkinline-linkstinymcewp-linkwplink
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced WPLink Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced WPLink has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "advanced-wplink" v1.1.0 plugin exhibits a mixed security posture, with some positive indicators but significant areas of concern stemming from its code analysis. Positively, the plugin has no reported vulnerabilities in its history and an absence of dangerous functions, external requests, file operations, or critical taint flows. However, the static analysis reveals several critical weaknesses. Notably, 100% of SQL queries are not using prepared statements, posing a significant risk of SQL injection. Furthermore, none of the outputs are properly escaped, leading to potential Cross-Site Scripting (XSS) vulnerabilities. The complete lack of capability checks on its entry points, while the attack surface is currently zero, indicates a potential for future risk if functionality is added without proper authorization checks. The absence of documented vulnerabilities is a strength, suggesting a history of stable code or a lack of dedicated security audits for this plugin. However, the identified code-level risks, particularly unescaped output and raw SQL queries, require immediate attention to prevent exploitation.

Key Concerns

  • SQL queries without prepared statements
  • 0% of outputs properly escaped
  • 0 capability checks on entry points
Vulnerabilities
None known

Advanced WPLink Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Advanced WPLink Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
9
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

0% escaped9 total outputs
Attack Surface

Advanced WPLink Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionadmin_noticesadvanced-wplink.php:26
actionadmin_initadvanced-wplink.php:31
actionplugins_loadedadvanced-wplink.php:44
actionplugins_loadedclass\Activate.php:8
actionadmin_initclass\Activate.php:10
actionwpmu_new_blogclass\Activate.php:27
actionadmin_noticesclass\Activate.php:71
actionadmin_menuclass\AdminPage.php:6
filterplugin_action_linksclass\AdminPage.php:7
filterplugin_row_metaclass\AdminPage.php:8
actionadmin_enqueue_scriptsclass\AdminPage.php:9
actionadmin_initclass\Editor.php:6
actionadmin_headclass\Editor.php:7
actionadmin_enqueue_scriptsclass\Editor.php:8
filtermce_external_pluginsclass\Editor.php:10
Maintenance & Trust

Advanced WPLink Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedJun 21, 2018
PHP min version
Downloads10K

Community Trust

Rating96/100
Number of ratings22
Active installs1K
Developer Profile

Advanced WPLink Developer Profile

Nico Martin

3 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced WPLink

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-wplink/assets/css/admin-styles.css/wp-content/plugins/advanced-wplink/assets/js/admin-page.min.js/wp-content/plugins/advanced-wplink/assets/css/admin-editor-styles.css
Script Paths
/wp-content/plugins/advanced-wplink/assets/js/admin-page.min.js
Version Parameters
advanced-wplink/assets/css/admin-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
awl_removeawl_styling_optionselement
HTML Comments
<!-- Update settings --><!-- Remove the inline linking tool from your WordPress Editor. --><!-- Add a "rel=nofollow" option to the link modal inside the Editor. --><!-- Add a "title" input field to the link modal inside the Editor. This way you can add a title attribute to your link. -->+7 more
Data Attributes
awl_nonce_nameawl_options_submitnm-awl_optionsawl_inline_linkawl_relawl_title+7 more
JS Globals
awl_relawl_vars
FAQ

Frequently Asked Questions about Advanced WPLink