
Blogroll Dropdown Links Security & Risk Analysis
wordpress.org/plugins/blogroll-dropdown-linksPlace your blogroll as a dropdown list in a widget area
Is Blogroll Dropdown Links Safe to Use in 2026?
Generally Safe
Score 92/100Blogroll Dropdown Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The blogroll-dropdown-links v1.0 plugin exhibits a mixed security posture. On the positive side, it has no known CVEs and a clean vulnerability history, suggesting a generally well-maintained codebase. Furthermore, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are positive indicators. However, significant concerns arise from the static analysis. The presence of a dangerous `create_function` call, a deprecated and often exploited PHP construct, poses a potential remote code execution risk if not handled with extreme care or if its usage is not strictly controlled. Additionally, a very low percentage of output is properly escaped (10%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into pages viewed by other users. The lack of nonce and capability checks across all entry points, although the attack surface is reported as zero, is a red flag that could become a significant weakness if any entry points are added or if the initial assessment is incomplete. The absence of any taint flows being analyzed is also a concern, as it means potential data manipulation vulnerabilities might have been overlooked.
In conclusion, while the plugin benefits from a lack of historical vulnerabilities and secure SQL handling, the critical `create_function` usage and pervasive unescaped output present substantial immediate risks. The absence of nonce and capability checks, coupled with the limited taint analysis, further contributes to an overall security posture that requires significant attention to mitigate potential XSS and code execution vulnerabilities. Developers should prioritize addressing these specific issues.
Key Concerns
- Presence of dangerous create_function()
- Low output escaping (10%)
- No nonce checks
- No capability checks
- No taint analysis performed
Blogroll Dropdown Links Security Vulnerabilities
Blogroll Dropdown Links Release Timeline
Blogroll Dropdown Links Code Analysis
Dangerous Functions Found
Output Escaping
Blogroll Dropdown Links Attack Surface
WordPress Hooks 3
Maintenance & Trust
Blogroll Dropdown Links Maintenance & Trust
Maintenance Signals
Community Trust
Blogroll Dropdown Links Alternatives
Blogroll Dropdown
blogroll-dropdown
Display links (blogroll) as dropdown select menu
Link Manager
link-manager
Enables the Link Manager that existed in WordPress until version 3.5.
Eazy Enable Blogroll
eazy-enable-blogroll
Eazy Enable Blogroll brings back the one and only WordPress Blogroll Feature, with nearly one click!
Link View
link-view
Display a link-list or link-slider in a post or page by using a shortcode.
Blogroll Links
blogroll-links
Display your blogroll links anywhere in posts or pages using a simple shortcode.
Blogroll Dropdown Links Developer Profile
1 plugin · 30 total installs
How We Detect Blogroll Dropdown Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blogroll-dropdown-links/css/widget.cssblogroll-dropdown-links/css/widget.css?ver=HTML / DOM Fingerprints
blogroll-dropdown-widget