
Broken Link Notifier Security & Risk Analysis
wordpress.org/plugins/broken-link-notifierGet notifications when a visitor loads a page with broken links
Is Broken Link Notifier Safe to Use in 2026?
Generally Safe
Score 96/100Broken Link Notifier has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "broken-link-notifier" v1.3.7.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in several areas, including a high percentage of properly escaped output and the use of prepared statements for a majority of its SQL queries. The absence of a broad attack surface through AJAX handlers, REST API routes, shortcodes, and cron events is also a strength. However, the presence of the `unserialize` function is a significant concern, as it is inherently risky and a common vector for remote code execution if not handled with extreme care and proper input validation, which is not explicitly detailed here. Furthermore, the plugin's vulnerability history, with three past CVEs including a high-severity one for SSRF and missing authorization, suggests a pattern of past security weaknesses. While there are currently no unpatched vulnerabilities, the historical context and the presence of `unserialize` warrant caution. The taint analysis showing flows with unsanitized paths, particularly those tagged as high severity, directly correlates with potential security risks that need to be thoroughly investigated and mitigated.
Key Concerns
- Presence of unserialize function
- High severity taint flows (4)
- Flows with unsanitized paths (7)
- Past high severity vulnerability history
- Past medium severity vulnerability history (2)
- File operations detected
- External HTTP requests detected
Broken Link Notifier Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Broken Link Notifier <= 1.3.5 - Missing Authorization
Broken Link Notifier <= 1.3.0 - Unauthenticated Server-Side Request Forgery
Broken Link Notifier <= 1.3.0 - Authenticated (Contributor+) CSV Injection
Broken Link Notifier Release Timeline
Broken Link Notifier Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Broken Link Notifier Attack Surface
WordPress Hooks 34
Maintenance & Trust
Broken Link Notifier Maintenance & Trust
Maintenance Signals
Community Trust
Broken Link Notifier Alternatives
Broken Link Checker by AIOSEO – Find & Fix Broken Internal, External & Video Links
broken-link-checker-seo
Broken link checker that finds and fixes broken links, broken images, and dead video links to protect your site's SEO.
Link Checker Pro
link-checker
An easy to use link checker for WordPress to detect broken links and images on your website.
External Links Overview
external-links-overview
Analyze, manage, and monitor all external links on your WordPress site. ---
Check for Broken Links – Broken Link Checker & 404 Monitor
check-for-broken-links
Broken link checker for WordPress. Find broken links, 404 errors, dead links and broken images. Automatic scans and AI fixes with Pro.
Archivarix Broken Links Recovery
archivarix-broken-links-recovery
Finds broken external and internal links and replaces them with Web Archive copies or manages them manually.
Broken Link Notifier Developer Profile
12 plugins · 3K total installs
How We Detect Broken Link Notifier
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/broken-link-notifier/includes/css/admin.css/wp-content/plugins/broken-link-notifier/includes/js/admin.js/wp-content/plugins/broken-link-notifier/includes/js/tinymce.jsbroken-link-notifier/includes/css/admin.css?ver=broken-link-notifier/includes/js/admin.js?ver=broken-link-notifier/includes/js/tinymce.js?ver=HTML / DOM Fingerprints
blnotifier-admin-wrapdata-blnotifier-scan-urlblnotifier_admin_vars