IM WP Linker Lite for WooCommerce Security & Risk Analysis

wordpress.org/plugins/im-wp-linker-lite-for-woocommerce

Internal Links Generator for Improve SEO (WooCommerce)

30 active installs v1.0.0 PHP + WP 4.6+ Updated Aug 5, 2025
internal-linkproductwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is IM WP Linker Lite for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

IM WP Linker Lite for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "im-wp-linker-lite-for-woocommerce" plugin, version 1.0.0, presents a mixed security posture. On the positive side, the absence of any known CVEs and a clean vulnerability history suggest a generally secure development practice or a lack of past exploitation. The plugin also shows good practices regarding SQL queries, with a high percentage utilizing prepared statements, and a complete lack of file operations and external HTTP requests, which are common vectors for compromise.

However, significant concerns arise from the static analysis. The complete lack of nonce checks and capability checks across all entry points (even though the entry point count is zero) is a major red flag. This indicates a reliance on WordPress's default security mechanisms, which are insufficient for many scenarios. Furthermore, while only two taint flows were analyzed, both exhibited unsanitized paths. Although not classified as critical or high severity, unsanitized paths represent potential avenues for injection attacks if an attacker can control the input that reaches these flows. The moderate percentage of properly escaped output also leaves room for potential cross-site scripting vulnerabilities.

In conclusion, the plugin's lack of historical vulnerabilities is a strength, but the static analysis reveals critical gaps in its security implementation, particularly concerning input sanitization and authorization checks. The unsanitized taint flows and the absence of explicit security checks on entry points are areas that require immediate attention to mitigate potential risks.

Key Concerns

  • No nonce checks
  • No capability checks
  • Taint flows with unsanitized paths (2/2)
  • Moderate output escaping (60% proper)
  • SQL queries not using prepared statements (2/12)
Vulnerabilities
None known

IM WP Linker Lite for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

IM WP Linker Lite for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
10 prepared
Unescaped Output
17
26 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

83% prepared12 total queries

Output Escaping

60% escaped43 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
plugin_menu (includes\im-wp-linker-lite-admin.php:160)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

IM WP Linker Lite for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedim-wp-linker-lite.php:95
actionwoocommerce_product_options_relatedincludes\im-wp-linker-lite-admin-product.php:151
actionwoocommerce_process_product_metaincludes\im-wp-linker-lite-admin-product.php:156
actionadmin_menuincludes\im-wp-linker-lite-admin.php:412
filterwoocommerce_product_get_upsell_idsincludes\im-wp-linker-lite-core.php:66
filterwoocommerce_upsells_columnsincludes\im-wp-linker-lite-core.php:67
filterwoocommerce_upsells_totalincludes\im-wp-linker-lite-core.php:68
Maintenance & Trust

IM WP Linker Lite for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.20
Last updatedAug 5, 2025
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

IM WP Linker Lite for WooCommerce Developer Profile

devimirochnik

2 plugins · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect IM WP Linker Lite for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/im-wp-linker-lite-for-woocommerce/assets/css/admin-style.css/wp-content/plugins/im-wp-linker-lite-for-woocommerce/assets/js/jquery.im-wp-linker-lite.html.helper.js
Script Paths
/wp-content/plugins/im-wp-linker-lite-for-woocommerce/assets/js/jquery.im-wp-linker-lite.html.helper.js
Version Parameters
im-wp-linker-lite-for-woocommerce/assets/css/admin-style.css?ver=im-wp-linker-lite-for-woocommerce/assets/js/jquery.im-wp-linker-lite.html.helper.js?ver=

HTML / DOM Fingerprints

CSS Classes
im-wp-linker-lite-wrap
Data Attributes
data-plugin-settings-page
JS Globals
IMWPLinkerLiteimWPLinkerLiteAdmin
FAQ

Frequently Asked Questions about IM WP Linker Lite for WooCommerce