
Extend Link Security & Risk Analysis
wordpress.org/plugins/extend-linkAdd classes, IDs, titles, rel attributes, and download options to links. Includes H1–H6 heading support and built-in link status checker for SEO.
Is Extend Link Safe to Use in 2026?
Generally Safe
Score 100/100Extend Link has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "extend-link" plugin v2.0.1 exhibits a strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates excellent security practices, with all identified entry points (a single AJAX handler) being properly protected by nonce and capability checks. The code also adheres to secure coding standards, evident in the complete absence of dangerous functions, file operations, and external HTTP requests. Furthermore, all SQL queries utilize prepared statements, and all outputs are properly escaped, mitigating common risks like SQL injection and Cross-Site Scripting (XSS). The lack of any recorded vulnerabilities, historical or current, further reinforces its secure reputation.
The analysis reveals no specific code-level risks such as unsanitized taint flows, raw SQL queries, or unescaped output. The only identified potential area of concern is the inclusion of the TinyMCE bundled library, which, if outdated, could theoretically introduce vulnerabilities. However, without specific version information for the bundled library, this remains a theoretical risk rather than a concrete one based on the provided data. The overall lack of attack surface and the meticulous implementation of security checks suggest a well-developed and secure plugin. The plugin's strengths lie in its robust authentication and sanitization measures, while its primary (and only notable) potential weakness lies in the unknown status of its bundled library.
Key Concerns
- Bundled library may be outdated
Extend Link Security Vulnerabilities
Extend Link Code Analysis
Bundled Libraries
Output Escaping
Extend Link Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Extend Link Maintenance & Trust
Maintenance Signals
Community Trust
Extend Link Alternatives
Nofollow for external link
nofollow-for-external-link
Automatically insert rel=nofollow and target=_blank to all the external links into your website posts, pages or menus. Support exclude domain.
Permalink Manager for WooCommerce
permalink-manager-for-woocommerce
Permalink Manager for WooCommerce improves your store permalinks and remove product, product_category and product_tag slugs from the URL.
Just TinyMCE Custom Styles
just-tinymce-styles
Adds dropdown options for custom css classes and attributes for tags in WordPress TinyMCE Editor.
WPF Force External Nofollow
wpf-force-external-nofollow
Automatically inserts rel="nofollow" into all the external links on your wordpress posts or pages.
Attributes Class ID Rel Title for WP-links
class-id-for-wp-links
Allow specify rel="nofollow", "title", "class" and "id" attributes for links in visual (TinyMCE) editor.
Extend Link Developer Profile
22 plugins · 33K total installs
How We Detect Extend Link
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/extend-link/css/tinymce-button-style.css/wp-content/plugins/extend-link/js/tinymce-button.js/wp-content/plugins/extend-link/js/tinymce-button.jsextend-link/css/tinymce-button-style.css?ver=2.0.1extend-link/js/tinymce-button.js?ver=2.0.1HTML / DOM Fingerprints
extendLink/wp-json/extend-link/v1/check-link-status