
CubeMage Smart Link Checker Security & Risk Analysis
wordpress.org/plugins/cubemage-smart-link-checkerA lightweight broken link checker for WordPress. Detects 404 errors, monitors affiliate links, and scans content with adjustable server load settings.
Is CubeMage Smart Link Checker Safe to Use in 2026?
Generally Safe
Score 100/100CubeMage Smart Link Checker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cubemage-smart-link-checker plugin v1.0.0 exhibits a concerning security posture primarily due to significant weaknesses in its entry point handling. While the static analysis revealed no dangerous functions, file operations, or bundled libraries, the presence of two AJAX handlers without any authentication or capability checks presents a substantial risk. This means that any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure within the WordPress environment. The lack of nonce checks further exacerbates this issue, making these handlers susceptible to Cross-Site Request Forgery (CSRF) attacks.
The SQL query usage is a mixed bag, with a considerable percentage not using prepared statements, which could lead to SQL injection vulnerabilities if not properly sanitized elsewhere. Similarly, the moderate rate of unescaped output raises concerns about Cross-Site Scripting (XSS) vulnerabilities. The absence of any recorded vulnerability history is a positive sign, suggesting that past versions may have been relatively secure or that the plugin hasn't been a significant target. However, this history does not negate the critical risks identified in the current code analysis.
In conclusion, the plugin has strengths in its lack of inherently dangerous functions and a clean vulnerability history. However, the critical absence of authentication and nonce checks on its AJAX entry points creates a significant and immediate security risk. The issues with SQL query preparation and output escaping, while less severe than the unauthenticated entry points, also require attention. The plugin's overall security is compromised by these fundamental oversights in handling user-initiated actions.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
- SQL queries not using prepared statements
- Unescaped output
CubeMage Smart Link Checker Security Vulnerabilities
CubeMage Smart Link Checker Code Analysis
SQL Query Safety
Output Escaping
CubeMage Smart Link Checker Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
CubeMage Smart Link Checker Maintenance & Trust
Maintenance Signals
Community Trust
CubeMage Smart Link Checker Alternatives
Link Checker Professional
link-checker
An easy to use link checker for WordPress to detect broken links and images on your website.
SEO Repair Kit – AI Chatbot, Schema Manager, SEO Content Monitoring, GSC Integration, Keyword & Rank Tracking
seo-repair-kit
The ultimate WordPress plugin for SEO automation - from link fixing to AI-powered schema generation and chatbot support.
Word 2 Cash
word-2-cash
Word 2 Cash is a free WordPress plugin. Its purpose is to turn specified keywords on your blog into links.
LinkAlert
codirun-linkalert
Link management and click tracking plugin for WordPress. Monitor clicks in real time, manage short links, and receive instant notifications.
Cute Broken Link Highlighter – Smart Broken Link Checker and Content Scanner
cute-broken-link-highlighter
Instantly detect and highlight broken links in your WordPress post editor. Works with both Classic Editor and Gutenberg Block Editor.
CubeMage Smart Link Checker Developer Profile
2 plugins · 0 total installs
How We Detect CubeMage Smart Link Checker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cubemage-smart-link-checker/assets/js/cubemage.jscubemage-smart-link-checker/assets/js/cubemage.js?ver=HTML / DOM Fingerprints
data-cm-urldata-cm-post-iddata-cm-link-typedata-cm-status-codedata-cm-last-checkeddata-cm-is-brokencm_vars/wp-json/cubemage-smart-link-checker/v1/scan/wp-json/cubemage-smart-link-checker/v1/status