All Post Statuses for Add Link Security & Risk Analysis

wordpress.org/plugins/all-post-statuses-for-add-link

Adds all post statuses to the "Add Link" modal in the editor, allowing you to link to future content, draft posts, private items etc.

10 active installs v1.1 PHP + WP 3.7+ Updated Oct 1, 2019
add-linkdraftfuturepost-statusscheduled
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is All Post Statuses for Add Link Safe to Use in 2026?

Generally Safe

Score 85/100

All Post Statuses for Add Link has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The security posture of the 'all-post-statuses-for-add-link' v1.1 plugin appears to be strong based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, file operations, or external HTTP requests is a positive sign. Furthermore, the fact that all SQL queries utilize prepared statements and all output is properly escaped demonstrates good development practices, reducing the risk of common vulnerabilities like SQL injection and cross-site scripting (XSS).

The static analysis reveals an extremely limited attack surface with zero entry points, including AJAX handlers, REST API routes, shortcodes, and cron events. This lack of exposed functionality significantly minimizes the opportunities for attackers to interact with the plugin in unexpected or malicious ways. Taint analysis also shows no identified flows with unsanitized paths, further reinforcing the plugin's apparent security.

The vulnerability history is equally encouraging, with no known CVEs, unpatched vulnerabilities, or recorded common vulnerability types. This suggests a history of stable and secure code. In conclusion, based on the data presented, this plugin exhibits excellent security characteristics. While the absence of capability checks and nonce checks on potential entry points (though none were found) could be a concern in plugins with a larger attack surface, the current minimal entry points mitigate this risk effectively.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

All Post Statuses for Add Link Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

All Post Statuses for Add Link Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

All Post Statuses for Add Link Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterwp_link_query_argsincludes\add-post-statuses.php:15
filterwp_link_query_argstrunk\includes\add-post-statuses.php:15
Maintenance & Trust

All Post Statuses for Add Link Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedOct 1, 2019
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings5
Active installs10
Developer Profile

All Post Statuses for Add Link Developer Profile

Dave Clements

4 plugins · 10K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect All Post Statuses for Add Link

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about All Post Statuses for Add Link