
FS Link Posts Security & Risk Analysis
wordpress.org/plugins/fs-link-postsFS Link Posts is a simple plugin to enable you to manually associate a post with other posts you’ve created.
Is FS Link Posts Safe to Use in 2026?
Generally Safe
Score 85/100FS Link Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The fs-link-posts plugin v0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, all identified SQL queries utilize prepared statements, and there are no detected file operations or external HTTP requests, which are common vectors for exploitation. The presence of both nonce and capability checks, although singular, indicates an awareness of basic WordPress security practices.
However, a significant concern arises from the complete lack of output escaping. With 6 total outputs identified and 0% properly escaped, this plugin is highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users without proper sanitization or escaping could be manipulated by attackers to inject malicious scripts. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign, but this is often a reflection of the plugin's limited functionality and attack surface rather than a guarantee of future security. The lack of taint analysis results could be due to the limited complexity or entry points of the plugin, but it doesn't negate the identified output escaping issue.
In conclusion, while the plugin is strong in preventing common injection and unauthorized access vulnerabilities due to its minimal entry points and secure SQL handling, the critical failure in output escaping presents a substantial risk of XSS. Developers should prioritize addressing this issue immediately. The absence of recorded vulnerabilities is positive but should not lead to complacency, especially given the identified XSS risk.
Key Concerns
- Unescaped output found
FS Link Posts Security Vulnerabilities
FS Link Posts Code Analysis
Output Escaping
FS Link Posts Attack Surface
WordPress Hooks 2
Maintenance & Trust
FS Link Posts Maintenance & Trust
Maintenance Signals
Community Trust
FS Link Posts Alternatives
CMS Tree Page View
cms-tree-page-view
Adds a tree view of all pages & custom posts. Get a great overview + options to drag & drop to reorder & option to add multiple pages.
No Page Comment
no-page-comment
An admin interface to control the default comment and trackback settings on new posts, pages and custom post types.
Posts in Page
posts-in-page
Easily add one or more posts to any page using simple shortcodes.
Author Filters
author-filters
Author filters plugin integrates an author filter drop down to sort listing on post, page, custom post type in admin.
Search by ID
search-by-id
Enables the user to search by post ID using the built-in search within the control panel. Works for all kinds of posts.
FS Link Posts Developer Profile
1 plugin · 10 total installs
How We Detect FS Link Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
fs-linked-postsfs-linked-postname="fs_linked_posts[]"name="fs_link_posts_noncename"id="fs_link_posts_noncename"