FP LinkedIn Company Profile Security & Risk Analysis

wordpress.org/plugins/fp-linkedin-company-profile

Bring your Company LinkedIn profile to your site to help users to follow your company in Linkedin. This plugin embed Company Profile summary card dire …

30 active installs v1.0.0 PHP + WP 2.0.0+ Updated Jul 5, 2013
companylinkedinprofilewidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FP LinkedIn Company Profile Safe to Use in 2026?

Generally Safe

Score 85/100

FP LinkedIn Company Profile has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "fp-linkedin-company-profile" plugin v1.0.0 exhibits a mixed security posture. On the positive side, the plugin has no known historical vulnerabilities, suggesting a generally stable development history. Furthermore, all SQL queries are correctly parameterized, and there are no file operations or external HTTP requests, which are common sources of vulnerabilities. The absence of any recorded CVEs is a strong indicator of good security practices in the past.

However, the static analysis reveals significant concerns. The use of the deprecated `create_function` is a major red flag, as it can be exploited for code injection if not handled with extreme care. More critically, the analysis shows that 100% of the plugin's output is unescaped. This represents a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website through user-supplied data that is later displayed. The lack of any identified taint flows or critical/high severity issues in the taint analysis is somewhat reassuring, but the unescaped output is a significant enough weakness on its own.

In conclusion, while the plugin benefits from a clean vulnerability history and good practices in data handling for SQL, the pervasive lack of output escaping and the use of `create_function` introduce substantial security risks, primarily related to XSS and potential code execution. These issues need immediate attention to improve the plugin's security posture.

Key Concerns

  • Dangerous function create_function used
  • 0% output escaping
Vulnerabilities
None known

FP LinkedIn Company Profile Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

FP LinkedIn Company Profile Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 16, 2026

FP LinkedIn Company Profile Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
28
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action( 'widgets_init', create_function('', 'return register_widget("LinkedinCompanyProfileWidgefp_linkedin_company_profile.php:108

Output Escaping

0% escaped28 total outputs
Attack Surface

FP LinkedIn Company Profile Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initfp_linkedin_company_profile.php:108
Maintenance & Trust

FP LinkedIn Company Profile Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedJul 5, 2013
PHP min version
Downloads4K

Community Trust

Rating20/100
Number of ratings2
Active installs30
Developer Profile

FP LinkedIn Company Profile Developer Profile

Flourish Pixel

6 plugins · 290 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FP LinkedIn Company Profile

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
//platform.linkedin.com/in.js

HTML / DOM Fingerprints

CSS Classes
LinkedinCompanyProfileWidget
Data Attributes
data-iddata-formatdata-textdata-related
JS Globals
IN
FAQ

Frequently Asked Questions about FP LinkedIn Company Profile