
del.icio.us for WordPress Security & Risk Analysis
wordpress.org/plugins/delicious-for-wordpressdel.icio.us for WordPress displays your latest del.icio.us bookmarks in your WordPress blog.
Is del.icio.us for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100del.icio.us for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'delicious-for-wordpress' v2.0.2 plugin exhibits a strong adherence to secure coding practices in several key areas, particularly concerning its attack surface. The absence of AJAX handlers, REST API routes, shortcodes, and cron events, coupled with the fact that all identified entry points are protected, significantly limits potential avenues for attack. Furthermore, the plugin demonstrates excellent SQL security by exclusively utilizing prepared statements, and it performs no file operations or external HTTP requests, which are common sources of vulnerabilities.
However, a critical concern arises from the output escaping analysis. With 100% of outputs being improperly escaped, this plugin presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data rendered by the plugin is susceptible to injection, potentially leading to the execution of malicious scripts in users' browsers. The lack of capability checks and nonce checks also contributes to a potential weakness, as these are fundamental security mechanisms for WordPress that are missing here. The vulnerability history being clean is a positive sign, but it does not negate the present risks identified in the static analysis.
In conclusion, while the plugin has a small attack surface and good practices in SQL handling and external interactions, the complete lack of output escaping is a major security flaw. This, combined with missing capability and nonce checks, creates a considerable risk of XSS and other injection-based attacks. Users of this plugin should be aware of these significant vulnerabilities, as they are present in the code itself and not just historical issues.
Key Concerns
- 100% of outputs not properly escaped
- No nonce checks
- No capability checks
del.icio.us for WordPress Security Vulnerabilities
del.icio.us for WordPress Code Analysis
Output Escaping
del.icio.us for WordPress Attack Surface
WordPress Hooks 3
Maintenance & Trust
del.icio.us for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
del.icio.us for WordPress Alternatives
DamnSexyBookmarks
damnsexybookmarks
Adds a social bookmarking menu to your posts/pages/index. Based on Josh Jones' SexyBookmarks plugin: http://eight7teen.com/sexy-bookmarks
Delicious XML Importer
delicious-xml-importer
Lets you import your Delicious bookmarks into WordPress as links, posts, or a custom post type.
Slickstream: Engagement and Conversions
slick-engagement
Use Slickstream to upgrade your site search. Get beautiful as-you-type search, relevant content recommendations, user favorites and more!
The Social Links
the-social-links
The Social Links plugin adds a widget and shortcode to your WordPress website allowing you to display icons linking to your social profiles.
Admin Starred Posts
admin-starred-posts
Mark posts, pages and custom posts in your WordPress admin; pretty similar to the stars feature in Gmail.
del.icio.us for WordPress Developer Profile
8 plugins · 1K total installs
How We Detect del.icio.us for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/delicious-for-wordpress/delicious.cssdelicious-for-wordpress/delicious.css?ver=HTML / DOM Fingerprints
deliciousdelicious-itemdelicious-linkdelicious-timestampdelicious-descdelicious-tagsdelicious-link-tagdelicious_title_linktitle