
App Link Generator Security & Risk Analysis
wordpress.org/plugins/app-link-generatorApp StoreとGoogle Play Storeのアプリインストールリンクをブロックエディタで簡単に表示できるプラグインです。
Is App Link Generator Safe to Use in 2026?
Generally Safe
Score 100/100App Link Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The app-link-generator plugin v1.2.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for all SQL queries, and all identified output is properly escaped, mitigating common injection and XSS vulnerabilities. The absence of file operations and dangerous functions further strengthens its core security. However, significant concerns arise from the unprotected REST API routes and the complete lack of nonces and capability checks for its entry points. This creates a substantial attack surface that is easily accessible to unauthenticated users. The taint analysis showing zero flows suggests that while direct data manipulation vulnerabilities might not be apparent in this specific analysis, the unprotected entry points could still be leveraged to trigger unintended behavior or interact with other parts of the application in unexpected ways.
The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. This suggests a potential for well-written code. However, the absence of vulnerabilities cannot compensate for the identified security weaknesses in the current version's implementation. The lack of authentication and authorization checks on REST API routes is a critical oversight. While the plugin's current functionality might not be sensitive, this design choice leaves it vulnerable to future expansion or exploitation by attackers who can trigger these endpoints without proper validation. Therefore, despite its strengths in data handling, the plugin requires immediate attention to address its unprotected entry points to improve its overall security.
Key Concerns
- REST API routes without permission callbacks
- AJAX handlers without auth checks
- Nonce checks missing
- Capability checks missing
App Link Generator Security Vulnerabilities
App Link Generator Release Timeline
App Link Generator Code Analysis
SQL Query Safety
Output Escaping
App Link Generator Attack Surface
REST API Routes 2
WordPress Hooks 4
Scheduled Events 1
Maintenance & Trust
App Link Generator Maintenance & Trust
Maintenance Signals
Community Trust
App Link Generator Alternatives
WP-Appbox
wp-appbox
With WP-Appbox you can add beautiful mobile app badges to your WordPress posts and pages simply by adding a shortcode.
Application download banner
application-download-banner
Plugin Description
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
App Link Generator Developer Profile
1 plugin · 0 total installs
How We Detect App Link Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/app-link-generator/build/index.js/wp-content/plugins/app-link-generator/build/style-index.css/wp-content/plugins/app-link-generator/build/index.jsapp-link-generator/build/index.js?ver=app-link-generator/build/style-index.css?ver=HTML / DOM Fingerprints
appligeBadgeImages/wp-json/app-link-generator/v1/search/wp-json/app-link-generator/v1/lookup