Exclude Attachment Link Suggestions Security & Risk Analysis

wordpress.org/plugins/exclude-link-suggestions

Removes attachment results from link suggestions in the Gutenberg block editor for a cleaner linking experience.

40 active installs v1.0.1 PHP 7.4+ WP 5.0+ Updated Feb 5, 2026
attachmentsblock-editorgutenberglinkssuggestions
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Exclude Attachment Link Suggestions Safe to Use in 2026?

Generally Safe

Score 100/100

Exclude Attachment Link Suggestions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'exclude-link-suggestions' plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. It reports zero entry points, dangerous functions, or SQL queries without prepared statements, indicating diligent coding practices. Furthermore, all identified outputs are properly escaped, and there are no file operations or external HTTP requests, significantly reducing the potential attack surface. The complete absence of known vulnerabilities in its history further reinforces its secure design.

While the static analysis indicates a clean codebase, the lack of nonce and capability checks on its entry points is a notable area of concern. Although the attack surface is currently reported as zero, if any functionality were to be added that exposed these entry points, the absence of these crucial security measures would create a significant risk of unauthorized access or manipulation. The bundled Freemius library, though not explicitly stated as outdated, also presents a potential risk if it contains known vulnerabilities or is not kept up-to-date.

In conclusion, 'exclude-link-suggestions' v1.0.1 appears to be a well-secured plugin with no currently exploitable vulnerabilities or critical code issues identified in the static analysis. Its adherence to secure coding principles like prepared statements and output escaping is commendable. However, the lack of authentication checks on potential future entry points and the inclusion of a bundled library warrant cautious monitoring.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • Bundled library (Freemius v1.0)
Vulnerabilities
None known

Exclude Attachment Link Suggestions Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Exclude Attachment Link Suggestions Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0
Attack Surface

Exclude Attachment Link Suggestions Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterrest_attachment_queryincludes\class-exclude-attachments-from-suggestions-core.php:16
Maintenance & Trust

Exclude Attachment Link Suggestions Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedFeb 5, 2026
PHP min version7.4
Downloads484

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

Exclude Attachment Link Suggestions Developer Profile

Small Plugins

7 plugins · 590 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Exclude Attachment Link Suggestions

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Exclude Attachment Link Suggestions