
FP LinkedIn Company Profile Security & Risk Analysis
wordpress.org/plugins/fp-linkedin-company-profileBring your Company LinkedIn profile to your site to help users to follow your company in Linkedin. This plugin embed Company Profile summary card dire …
Is FP LinkedIn Company Profile Safe to Use in 2026?
Generally Safe
Score 85/100FP LinkedIn Company Profile has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "fp-linkedin-company-profile" plugin v1.0.0 exhibits a mixed security posture. On the positive side, the plugin has no known historical vulnerabilities, suggesting a generally stable development history. Furthermore, all SQL queries are correctly parameterized, and there are no file operations or external HTTP requests, which are common sources of vulnerabilities. The absence of any recorded CVEs is a strong indicator of good security practices in the past.
However, the static analysis reveals significant concerns. The use of the deprecated `create_function` is a major red flag, as it can be exploited for code injection if not handled with extreme care. More critically, the analysis shows that 100% of the plugin's output is unescaped. This represents a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website through user-supplied data that is later displayed. The lack of any identified taint flows or critical/high severity issues in the taint analysis is somewhat reassuring, but the unescaped output is a significant enough weakness on its own.
In conclusion, while the plugin benefits from a clean vulnerability history and good practices in data handling for SQL, the pervasive lack of output escaping and the use of `create_function` introduce substantial security risks, primarily related to XSS and potential code execution. These issues need immediate attention to improve the plugin's security posture.
Key Concerns
- Dangerous function create_function used
- 0% output escaping
FP LinkedIn Company Profile Security Vulnerabilities
FP LinkedIn Company Profile Release Timeline
FP LinkedIn Company Profile Code Analysis
Dangerous Functions Found
Output Escaping
FP LinkedIn Company Profile Attack Surface
WordPress Hooks 1
Maintenance & Trust
FP LinkedIn Company Profile Maintenance & Trust
Maintenance Signals
Community Trust
FP LinkedIn Company Profile Alternatives
WP LinkedIn Auto Publish
wp-linkedin-auto-publish
WP LinkedIn Auto Publish automatically publishes posts, custom posts and pages to your LinkedIn profile and/or company pages.
Footer widget bundle
footer-widget-bundle
Footer widget bundle includes company information, latest post, contact address and opening hours.
FP LinkedIn Profile
fp-linkedin-profile
Bring your LinkedIn profiles to your site to help users discover common professional connections. This plugin embed Profile summary card directly on y …
Astra Widgets
astra-widgets
Quickest solution to add widgets like Address, Social Profiles and List icons on a website built with Astra.
Lightweight Social Icons
lightweight-social-icons
Looking to add simple social icons to your widget areas? Choose the size and color of your icons, and then choose from 47 different social profiles.
FP LinkedIn Company Profile Developer Profile
6 plugins · 290 total installs
How We Detect FP LinkedIn Company Profile
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
//platform.linkedin.com/in.jsHTML / DOM Fingerprints
LinkedinCompanyProfileWidgetdata-iddata-formatdata-textdata-relatedIN