
Hikari Internal Links Security & Risk Analysis
wordpress.org/plugins/hikari-internal-linksHikari Internal Links provides a shortcode that dynamically generates to most Wordpress pages, like posts, comments, categories, feeds.
Is Hikari Internal Links Safe to Use in 2026?
Generally Safe
Score 85/100Hikari Internal Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hikari-internal-links" plugin exhibits a mixed security posture. On one hand, it demonstrates good practices by utilizing prepared statements for all SQL queries and not making external HTTP requests. The absence of known CVEs and a clean vulnerability history is also a positive sign. However, significant concerns arise from the static analysis results, particularly the complete lack of output escaping. This means that any data processed by the plugin and displayed to users could be susceptible to Cross-Site Scripting (XSS) attacks. Additionally, the taint analysis revealed two flows with unsanitized paths, indicating potential vulnerabilities where user-controlled input might be used in file operations or other path-dependent actions without proper sanitization, although these were not classified as critical or high severity in the provided data. The absence of nonce checks on its entry points (shortcodes) further increases the risk of Cross-Site Request Forgery (CSRF) if the shortcodes can be triggered with malicious intent.
While the plugin has a small attack surface and no recorded critical vulnerabilities, the lack of output escaping presents a substantial risk of XSS. The presence of unsanitized paths, even without higher severity classification, warrants attention. The absence of nonce checks on shortcodes is another area of concern. The plugin's strengths lie in its database query security and lack of external dependencies. However, the critical weakness in output escaping and the presence of unsanitized paths must be addressed to improve its overall security.
Key Concerns
- All outputs are unescaped
- Taint analysis shows unsanitized paths
- No nonce checks on entry points
Hikari Internal Links Security Vulnerabilities
Hikari Internal Links Release Timeline
Hikari Internal Links Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Hikari Internal Links Attack Surface
Shortcodes 2
WordPress Hooks 4
Maintenance & Trust
Hikari Internal Links Maintenance & Trust
Maintenance Signals
Community Trust
Hikari Internal Links Alternatives
Terms to Links
terms-to-links
This plugin will automatically link term names in your content to that term's detail page.
WP No Base Permalink
wp-no-base-permalink
Removes category base or parents categories or tag base from your permalinks. Compatible with WPML Plugin and WordPress Multisite.
Blog Filter Post Filtering
blog-filter
Blog Filter helps users display posts in filterable grid and masonry layouts. Organize content by categories or tags with customizable designs.
Archive Title
archive-title
Provides options to control an archive page title.
Custom Recent Posts Widget
custom-recent-posts-widget
A widget to show recent posts list based on categories or tags
Hikari Internal Links Developer Profile
9 plugins · 430 total installs
How We Detect Hikari Internal Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hikari-internal-links/css/hikari-internal-links.csshikari-internal-links/css/hikari-internal-links.css?ver=