[CR]Paid Link Manager Security & Risk Analysis

wordpress.org/plugins/crpaid-link-manager

A plugin that will help you manage your paid link's life cycle

10 active installs v0.6 PHP + WP 3.0+ Updated Mar 11, 2026
custom-tablepaid-linksidebarwidget
99
A · Safe
CVEs total1
Unpatched0
Last CVEMar 17, 2026
Safety Verdict

Is [CR]Paid Link Manager Safe to Use in 2026?

Generally Safe

Score 99/100

[CR]Paid Link Manager has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 17, 2026Updated 27d ago
Risk Assessment

The crpaid-link-manager plugin version 0.6 exhibits a generally good security posture, with no critical or high-severity vulnerabilities identified in its static analysis or historical data. The plugin demonstrates strong adherence to secure coding practices by utilizing prepared statements for a significant majority of its SQL queries and properly escaping most of its output. The absence of file operations and external HTTP requests further reduces its attack surface. Furthermore, the plugin has no recorded CVEs, indicating a clean security history. However, a notable weakness is the complete absence of capability checks for its entry points. While the current version has a small attack surface, this lack of authorization checks presents a potential risk if new entry points are added or if existing ones are inadvertently exposed to unauthorized users in future updates. The plugin also has a moderate number of SQL queries, and while most are prepared, a small percentage are not, which could represent a minor risk if those queries are susceptible to injection. Overall, the plugin is well-developed from a security perspective, but the missing capability checks are a significant area for improvement.

Key Concerns

  • No capability checks on entry points
  • Some SQL queries not using prepared statements
  • Some output not properly escaped
Vulnerabilities
1

[CR]Paid Link Manager Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-1780medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

[CR]Paid Link Manager <= 0.5 - Reflected Cross-Site Scripting

Mar 17, 2026 Patched in 0.6 (1d)
Version History

[CR]Paid Link Manager Release Timeline

v0.6Current
v0.51 CVE
v0.41 CVE
v0.31 CVE
v0.21 CVE
v0.11 CVE
vtags1 CVE
Code Analysis
Analyzed Mar 17, 2026

[CR]Paid Link Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
20 prepared
Unescaped Output
22
74 escaped
Nonce Checks
6
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

80% prepared25 total queries

Output Escaping

77% escaped96 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
cr_paid_link_manager_admin_menu (cr-paidlinkmanager.php:58)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

[CR]Paid Link Manager Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[paid_links] cr-paidlinkmanager.php:460
WordPress Hooks 5
actioninitcr-paidlinkmanager.php:31
actionadmin_menucr-paidlinkmanager.php:50
actionadmin_initcr-paidlinkmanager.php:374
actioncr_paid_link_manager_generate_expiring_link_email_actioncr-paidlinkmanager.php:398
actionwidgets_initcr-paidlinkmanager.php:522

Scheduled Events 2

cr_paid_link_manager_generate_expiring_link_email_action
cr_paid_link_manager_generate_expiring_link_email_action
Maintenance & Trust

[CR]Paid Link Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

[CR]Paid Link Manager Developer Profile

Arief Bayu Purwanto

4 plugins · 40 total installs

92
trust score
Avg Security Score
89/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect [CR]Paid Link Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/crpaid-link-manager/css/crpaidlinkmanager.css/wp-content/plugins/crpaid-link-manager/js/crpaidlinkmanager.js
Script Paths
/wp-content/plugins/crpaid-link-manager/js/crpaidlinkmanager.js
Version Parameters
crpaid-link-manager/css/crpaidlinkmanager.css?ver=crpaid-link-manager/js/crpaidlinkmanager.js?ver=

HTML / DOM Fingerprints

CSS Classes
wrap
HTML Comments
FIXME: to be defined
Data Attributes
id='crpost2pingfm-warning'class='updated fade'
FAQ

Frequently Asked Questions about [CR]Paid Link Manager