
Footer Links Commando Security & Risk Analysis
wordpress.org/plugins/footer-links-commandoCreates links at the footer of your wordpress site in sections identical to what you can do with the blog roll in sidebar.
Is Footer Links Commando Safe to Use in 2026?
Generally Safe
Score 85/100Footer Links Commando has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'footer-links-commando' plugin version 1.0.3 presents a mixed security profile. On the positive side, there are no known CVEs, the plugin utilizes prepared statements for all its SQL queries, and it does not perform file operations or external HTTP requests, which are common vectors for vulnerabilities. The limited attack surface with zero AJAX handlers, REST API routes, shortcodes, or cron events is also a good indicator. However, significant concerns arise from the static analysis. The presence of two 'unserialize' calls without any accompanying nonce or capability checks on the code paths where they are used represents a critical security risk. Furthermore, a concerning 100% of output appears to be unescaped, making it highly susceptible to Cross-Site Scripting (XSS) attacks. The single taint flow identified as having unsanitized paths, even if not classified as critical or high, combined with unescaped output, further exacerbates the XSS risk. The absence of any vulnerability history is a positive sign, suggesting the plugin has historically been secure or has not been targeted. However, this does not mitigate the direct risks identified in the current code analysis.
Key Concerns
- Dangerous function 'unserialize' used without checks
- 100% of output unescaped
- Taint flow with unsanitized paths
- No nonce checks
- Limited capability checks for dangerous functions
Footer Links Commando Security Vulnerabilities
Footer Links Commando Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Footer Links Commando Attack Surface
WordPress Hooks 7
Maintenance & Trust
Footer Links Commando Maintenance & Trust
Maintenance Signals
Community Trust
Footer Links Commando Alternatives
Acknowledgify
acknowledgify
Acknowledgify lets agencies, freelancers, and developers add credits to WordPress sites via humans.txt, meta tags, and footer links.
Dynamic Copyright Year
dynamic-copyright-year
Take year updates off your New Year’s list. This plugin dynamically updates copyright year in realtime with local timezone precision. No shortcode.
WP About Author
wp-about-author
Easily display customizable author bios below your posts
Enhanced Linking
enhanced-linking
This plugin enhances the Insert/Edit Link dialogue by letting users select and find additional content from their blog and external web.
Relative URL for Img and A Tags
relative-url-for-img-and-a-tags
This plugin will filter the content of your posts and pages to remove the root of the domain from links and image sources.
Footer Links Commando Developer Profile
3 plugins · 30 total installs
How We Detect Footer Links Commando
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/footer-links-commando/oo/FLC.phpfooter-links-commando/style.css?ver=1.0.3HTML / DOM Fingerprints
af-form-fb-1981928789af-form-1981928789