Definitions – Internal Linkbuilding Security & Risk Analysis

wordpress.org/plugins/definitions-internal-linkbuilding

Automatically replace your posts' keywords on your website with an internal link and tooltip.

20 active installs v1.0.2 PHP 5.6+ WP 5.2+ Updated May 6, 2022
coolhyperlinkslinkbuildingtooltips
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Definitions – Internal Linkbuilding Safe to Use in 2026?

Generally Safe

Score 85/100

Definitions – Internal Linkbuilding has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "definitions-internal-linkbuilding" plugin version 1.0.2 demonstrates several positive security practices, including the complete absence of known CVEs and the consistent use of prepared statements for all SQL queries. The code also shows a reasonable number of capability checks and a single nonce check, which are good indicators of security awareness during development. However, the analysis reveals a significant concern regarding the attack surface. With 5 AJAX handlers, 3 of which lack authentication checks, there's a clear vulnerability to unauthorized access and potential exploitation of the plugin's functionality. The limited number of taint flows analyzed (zero) makes it difficult to assess the risk of data manipulation or injection, but the lack of sanitization for unsanitized paths is a concerning signal, even with no critical or high severity flows detected. The plugin's output escaping is also a mixed bag, with 62% properly escaped, suggesting some areas may be vulnerable to cross-site scripting (XSS) attacks. Overall, while the plugin avoids common pitfalls like unpatched vulnerabilities and raw SQL queries, the unprotected AJAX endpoints represent a substantial risk that needs immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Limited output escaping (62% proper)
  • Zero taint flows analyzed, potential for hidden risks
Vulnerabilities
None known

Definitions – Internal Linkbuilding Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Definitions – Internal Linkbuilding Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
7 prepared
Unescaped Output
14
23 escaped
Nonce Checks
1
Capability Checks
9
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared7 total queries

Output Escaping

62% escaped37 total outputs
Attack Surface
3 unprotected

Definitions – Internal Linkbuilding Attack Surface

Entry Points5
Unprotected3

AJAX Handlers 5

authwp_ajax_dismiss_review_noticereview.php:62
authwp_ajax_rspdef_cancel_tourshepherd\tour.php:25
noprivwp_ajax_rspdef_load_previewtext_parser.php:14
authwp_ajax_rspdef_load_previewtext_parser.php:15
authwp_ajax_rspdef_scan_definition_counttext_parser.php:16
WordPress Hooks 16
actionplugins_loadeddefinitions.php:157
actioninitpost_type.php:7
actionadd_meta_boxespost_type.php:8
actionsave_postpost_type.php:9
actionadmin_enqueue_scriptspost_type.php:10
actionadmin_initreview.php:21
actionadmin_initreview.php:22
actionadmin_noticesreview.php:65
actionadmin_print_footer_scriptsreview.php:67
actionadmin_initshepherd\tour.php:26
actionadmin_enqueue_scriptsshepherd\tour.php:27
actionwp_enqueue_scriptstext_parser.php:11
actionscript_loader_tagtext_parser.php:12
filterthe_contenttext_parser.php:13
actionsave_posttext_parser.php:17
actiondelete_termtext_parser.php:18
Maintenance & Trust

Definitions – Internal Linkbuilding Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedMay 6, 2022
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Definitions – Internal Linkbuilding Developer Profile

Rogier Lankhorst

2 plugins · 200K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Definitions – Internal Linkbuilding

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/definitions-internal-linkbuilding/admin/css/rspdef.admin.css/wp-content/plugins/definitions-internal-linkbuilding/admin/css/rspdef.admin-rtl.css/wp-content/plugins/definitions-internal-linkbuilding/admin/js/rspdef.admin.js/wp-content/plugins/definitions-internal-linkbuilding/shepherd/js/shepherd.min.js/wp-content/plugins/definitions-internal-linkbuilding/shepherd/css/shepherd-theme-arrows.css
Script Paths
/wp-content/plugins/definitions-internal-linkbuilding/admin/js/rspdef.admin.js/wp-content/plugins/definitions-internal-linkbuilding/shepherd/js/shepherd.min.js
Version Parameters
definitions-internal-linkbuilding/admin/css/rspdef.admin.css?ver=definitions-internal-linkbuilding/admin/css/rspdef.admin-rtl.css?ver=definitions-internal-linkbuilding/admin/js/rspdef.admin.js?ver=definitions-internal-linkbuilding/shepherd/js/shepherd.min.js?ver=definitions-internal-linkbuilding/shepherd/css/shepherd-theme-arrows.css?ver=

HTML / DOM Fingerprints

CSS Classes
rspdef-definition-edit-formrspdef-definition-rowrspdef-definition-inputrspdef-definition-tooltip-preview
HTML Comments
Copyright 2021 Really Simple Plugins (email : support@really-simple-plugins.com)
Data Attributes
data-rspdef-definition-iddata-rspdef-definition-termdata-rspdef-definition-tooltip
JS Globals
rspdef_admin
FAQ

Frequently Asked Questions about Definitions – Internal Linkbuilding