Comment Link Manager Security & Risk Analysis

wordpress.org/plugins/comment-link-manager

CLM enables admins to disable author links, open links in new window, and remove the nofollow tag from links that are left in comments by visitors.

10 active installs v1.1 PHP + WP 2.8+ Updated Nov 14, 2011
author-linkscommentsnew-windownofollowspam
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Comment Link Manager Safe to Use in 2026?

Generally Safe

Score 85/100

Comment Link Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The "comment-link-manager" v1.1 plugin exhibits a mixed security posture. On the positive side, the plugin has a very small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential entry points for attackers. The code also shows a strong reliance on prepared statements for its SQL queries, with 89% being properly handled. Furthermore, there is no history of known vulnerabilities (CVEs), suggesting a history of secure development or a lack of past significant issues.

However, several concerns arise from the static analysis. The most significant is the taint analysis, which identified 2 flows with unsanitized paths, categorized as high severity. This indicates potential vulnerabilities where user-supplied data might not be properly validated or sanitized before being used in a way that could be exploited. Additionally, the output escaping is notably low, with only 17% of outputs being properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if untrusted data is directly rendered in the frontend without adequate sanitization.

While the plugin has no recorded CVEs, the presence of high-severity taint flows and poor output escaping necessitates caution. The lack of vulnerability history is a positive sign, but it does not negate the immediate risks identified in the current code analysis. Overall, the plugin has a robust foundation in terms of attack surface and SQL handling, but critical attention must be paid to the identified taint flows and output escaping mechanisms to mitigate potential security risks.

Key Concerns

  • High severity unsanitized taint flows found
  • Low percentage of properly escaped output
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Comment Link Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Comment Link Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
8 prepared
Unescaped Output
24
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

89% prepared9 total queries

Output Escaping

17% escaped29 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
clm_adminPage (comment-link-manager.php:199)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Comment Link Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterget_comment_author_linkcomment-link-manager.php:83
filtercomment_textcomment-link-manager.php:105
filterget_comment_author_urlcomment-link-manager.php:162
actionadmin_menucomment-link-manager.php:366
Maintenance & Trust

Comment Link Manager Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedNov 14, 2011
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Comment Link Manager Developer Profile

rrolfe

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Comment Link Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/comment-link-manager/comment-link-manager.css
Version Parameters
comment-link-manager/comment-link-manager.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Comment Link Manager