
LinkAlert Security & Risk Analysis
wordpress.org/plugins/codirun-linkalertLink management and click tracking plugin for WordPress. Monitor clicks in real time, manage short links, and receive instant notifications.
Is LinkAlert Safe to Use in 2026?
Generally Safe
Score 100/100LinkAlert has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The codirun-linkalert plugin, in version 1.0.4, exhibits a mixed security posture. Its strengths lie in its robust use of prepared statements for SQL queries (97%) and a significant number of nonce and capability checks (30 and 42 respectively), indicating an awareness of common WordPress security practices. The absence of known CVEs and a clean vulnerability history further contribute to a generally positive outlook.
However, there are notable areas of concern. The presence of 18 AJAX handlers, with one completely lacking authentication checks, presents a significant attack vector. This unprotected entry point could allow unauthorized users to trigger plugin functionality. Additionally, the taint analysis revealed two flows with unsanitized paths. While not classified as critical or high severity, unsanitized paths can still lead to unexpected behavior or potential exploits if not properly handled. The output escaping also shows room for improvement, with 43% of outputs not being properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities.
In conclusion, while codirun-linkalert has a clean vulnerability history and good practices in many areas, the unprotected AJAX handler and unsanitized paths are critical issues that require immediate attention. The percentage of unescaped output is also a concern that should be addressed to improve the overall security of the plugin.
Key Concerns
- AJAX handler without auth check
- Flows with unsanitized paths
- Low percentage of properly escaped output
LinkAlert Security Vulnerabilities
LinkAlert Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
LinkAlert Attack Surface
AJAX Handlers 18
WordPress Hooks 20
Maintenance & Trust
LinkAlert Maintenance & Trust
Maintenance Signals
Community Trust
LinkAlert Alternatives
ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing
shortlinkspro
Shorten, track, manage and share any URL using your own domain name!
LinkFiliate – Advanced Affiliate Link Management, Branded Short Links, Click Tracking & Analytics
linkfiliate
Create pretty branded URLs, cloak affiliate links, and track clicks in real time — giving you better control of all your marketing links in WordPress.
URL Shortify – Simple and Easy URL Shortener
url-shortify
URL Shortify helps you beautify, manage, share & cloak any links on or off your WordPress website. Create links using your domain name!
Custom Link Shortener
custom-link-shortener
Advanced URL shortener for WordPress with analytics, link rotation, location tracking, random redirects, and password protection.
Royal Links
royal-links
A powerful WordPress link management plugin for shortening, tracking, and organizing your links.
LinkAlert Developer Profile
2 plugins · 10 total installs
How We Detect LinkAlert
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/codirun-linkalert/assets/css/linkalert-style.css/wp-content/plugins/codirun-linkalert/assets/js/linkalert-script.js/wp-content/plugins/codirun-linkalert/assets/js/linkalert-script.jscodirun-linkalert/assets/css/linkalert-style.css?ver=codirun-linkalert/assets/js/linkalert-script.js?ver=HTML / DOM Fingerprints
codirun_link_alert_message<!-- BEGIN LINKALERT HTML REDIRECT --><!-- END LINKALERT HTML REDIRECT --><!-- BEGIN LINKALERT JAVASCRIPT REDIRECT --><!-- END LINKALERT JAVASCRIPT REDIRECT -->data-codirun-target-urldata-codirun-status-codedata-codirun-nofollowdata-codirun-sponsoredwindow.codirun_linkalert_redirect_options