CM Curated List Manager – Effortless tool for link management Security & Risk Analysis

wordpress.org/plugins/cm-curated-list-manager

Create and manage curated lists and manage links with this content curation plugin. Share & Organize content, resources, links, images and engage …

80 active installs v1.2.9 PHP 5.2.4+ WP 5.4.0+ Updated Jan 28, 2026
bookmarkscontent-curationcontent-managementlink-managerlist-manager
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CM Curated List Manager – Effortless tool for link management Safe to Use in 2026?

Generally Safe

Score 100/100

CM Curated List Manager – Effortless tool for link management has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "cm-curated-list-manager" plugin, version 1.2.9, presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and implementing a reasonable number of nonce checks. The absence of known CVEs and historical vulnerabilities is also a strong indicator of a generally well-maintained codebase. However, significant concerns arise from the static analysis, particularly the presence of 3 AJAX handlers without authentication checks, creating a considerable attack surface that could be exploited by unauthenticated users. Furthermore, the low percentage (39%) of properly escaped output suggests a risk of cross-site scripting (XSS) vulnerabilities, allowing for potential code injection if untrusted data is rendered improperly. While taint analysis did not reveal critical or high-severity unsanitized paths, the overall lack of robust input validation and authentication on key entry points warrants caution.

Key Concerns

  • AJAX handlers without auth checks
  • Low output escaping percentage
Vulnerabilities
None known

CM Curated List Manager – Effortless tool for link management Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

CM Curated List Manager – Effortless tool for link management Release Timeline

v1.2.8
v1.2.7
v1.2.6
v1.2.5
v1.2.4
v1.2.3
v1.2.2
Code Analysis
Analyzed Mar 16, 2026

CM Curated List Manager – Effortless tool for link management Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
199
128 escaped
Nonce Checks
5
Capability Checks
1
File Operations
1
External Requests
5
Bundled Libraries
0

Output Escaping

39% escaped327 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

5 flows3 with unsanitized paths
cminds_system_info_content (package\cminds-free.php:2728)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

CM Curated List Manager – Effortless tool for link management Attack Surface

Entry Points8
Unprotected3

AJAX Handlers 4

authwp_ajax_cm-submit-uninstall-reasonpackage\cminds-free.php:147
authwp_ajax_cm-submit-registration-emailpackage\cminds-free.php:148
authwp_ajax_cm-submit-deregistrationpackage\cminds-free.php:149
authwp_ajax_cm-submit-registration-skippackage\cminds-free.php:150

Shortcodes 4

[cminds_free_registration] package\cminds-free.php:54
[cminds_free_guide] package\cminds-free.php:55
[cminds_upgrade_box] package\cminds-free.php:56
[cminds_free_activation] package\cminds-free.php:57
WordPress Hooks 33
actionactivated_pluginpackage\cminds-free.php:31
actionadmin_initpackage\cminds-free.php:33
actionadmin_menupackage\cminds-free.php:34
actionadmin_enqueue_scriptspackage\cminds-free.php:35
actionadmin_enqueue_scriptspackage\cminds-free.php:36
actioncminds_download_sysinfopackage\cminds-free.php:48
actioninitpackage\cminds-free.php:50
actioninitpackage\cminds-free.php:51
filterplugin_row_metapackage\cminds-free.php:59
actionwp_dashboard_setuppackage\cminds-free.php:62
actionadmin_footerpackage\cminds-free.php:157
filterwp_mail_content_typepackage\cminds-free.php:311
filterwp_mail_content_typepackage\cminds-free.php:2078
filterwp_mail_content_typepackage\cminds-free.php:2169
actioninitplugin\notices\AdminNoticeManager.php:12
actionadmin_noticesplugin\notices\AdminNoticeManager.php:13
actioninitplugin\options\Options.php:19
actionadmin_menuplugin\options\Options.php:20
actionadmin_menuplugin\PluginAbstract.php:20
actioninitplugin\PluginAbstract.php:21
actioninitplugin\shortcodes\Shortcode.php:14
actioninitplugin\shortcodes\Shortcode.php:15
actionadmin_menuplugin\taxonomies\CategoryTaxonomy.php:13
actionadmin_headplugin\taxonomies\CategoryTaxonomy.php:14
actionadmin_menuplugin\taxonomies\LinkTaxonomy.php:17
actionadmin_headplugin\taxonomies\LinkTaxonomy.php:18
actionpre_delete_termplugin\taxonomies\LinkTaxonomy.php:23
actionedit_termsplugin\taxonomies\LinkTaxonomy.php:24
actionquick_edit_custom_boxplugin\taxonomies\LinkTaxonomy.php:25
filterget_terms_defaultsplugin\taxonomies\LinkTaxonomy.php:29
actioninitplugin\taxonomies\TaxonomyAbstract.php:11
filterparent_fileplugin\taxonomies\TaxonomyAbstract.php:12
actionadmin_enqueue_scriptsplugin\taxonomies\TaxonomyAbstract.php:13
Maintenance & Trust

CM Curated List Manager – Effortless tool for link management Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 28, 2026
PHP min version5.2.4
Downloads16K

Community Trust

Rating100/100
Number of ratings2
Active installs80
Developer Profile

CM Curated List Manager – Effortless tool for link management Developer Profile

CreativeMindsSolutions

19 plugins · 22K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
535 days
View full developer profile
Detection Fingerprints

How We Detect CM Curated List Manager – Effortless tool for link management

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cm-curated-list-manager/package/css/frontend.css/wp-content/plugins/cm-curated-list-manager/package/css/backend.css/wp-content/plugins/cm-curated-list-manager/package/js/backend.js
Script Paths
/wp-content/plugins/cm-curated-list-manager/package/js/backend.js
Version Parameters
cm-curated-list-manager/package/css/frontend.css?ver=cm-curated-list-manager/package/css/backend.css?ver=cm-curated-list-manager/package/js/backend.js?ver=

HTML / DOM Fingerprints

CSS Classes
cm-list-manager
Data Attributes
data-cm-list-manager-list-id
JS Globals
cm_list_manager_settings
Shortcode Output
[cminds_free_registration][cminds_free_guide][cminds_upgrade_box][cminds_free_activation]
FAQ

Frequently Asked Questions about CM Curated List Manager – Effortless tool for link management