
Hyperlink Group Block Security & Risk Analysis
wordpress.org/plugins/hyperlink-group-blockCombine blocks into a group wrapped with an hyperlink (<a>).
Is Hyperlink Group Block Safe to Use in 2026?
Generally Safe
Score 99/100Hyperlink Group Block has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the hyperlink-group-block plugin v2.0.5 indicates a generally strong security posture. The absence of any dangerous functions, file operations, external HTTP requests, or SQL queries executed without prepared statements is commendable. Furthermore, all identified output is properly escaped, and there are no critical or high-severity taint flows. This suggests the core code is well-written and resistant to common attack vectors.
However, a significant concern arises from the plugin's vulnerability history. The presence of two known medium-severity CVEs, both related to Cross-Site Scripting (XSS), is a red flag. While these appear to be patched in the current version, it indicates past weaknesses that attackers could have exploited. The complete lack of capability checks and nonce checks across all entry points, combined with zero AJAX handlers and REST API routes, is unusual. While this contributes to a small attack surface from a direct exploitation standpoint, it also means that if any vulnerabilities were to be introduced in the future, they might be exploitable without robust authorization mechanisms. The absence of any taint flows in the current analysis is positive, but the historical XSS issues warrant continued vigilance.
Key Concerns
- Two medium severity CVEs previously existed
- No capability checks on entry points
- No nonce checks on entry points
Hyperlink Group Block Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Hyperlink Group Block <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Hyperlink Group Block <= 1.17.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Hyperlink Group Block Code Analysis
Output Escaping
Hyperlink Group Block Attack Surface
WordPress Hooks 2
Maintenance & Trust
Hyperlink Group Block Maintenance & Trust
Maintenance Signals
Community Trust
Hyperlink Group Block Alternatives
Advanced Link Block
advanced-link-block
Turn any block into a clickable link in the Gutenberg editor, with advanced options like phone, email, download, and more.
Custom Anchor Block
custom-anchor-block
Add customizable anchor links as text or buttons with custom colors to create smooth in-page navigation in WordPress.
Button Block – Design Stylish, Interactive, and Multi-Functional Buttons
button-block
Get multi-functional buttons
Anchor Block
anchor-block
Anchor Block let you generate internal link to any section of your Gutenberg pages.
Clickable Blocks
clickable-blocks
Transform blocks into clickable links effortlessly with 'Clickable Blocks' – enhance user engagement instantly!
Hyperlink Group Block Developer Profile
6 plugins · 11K total installs
How We Detect Hyperlink Group Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hyperlink-group-block/build/view.asset.php/wp-content/plugins/hyperlink-group-block/build/index.asset.php/wp-content/plugins/hyperlink-group-block/build/view.js/wp-content/plugins/hyperlink-group-block/build/index.jshyperlink-group-block/build/view.js?ver=hyperlink-group-block/build/index.js?ver=HTML / DOM Fingerprints
wp-block-tiptip-hyperlink-group-blockdata-link-targetdata-reldata-aria-labeldata-title