
Plugin Name: Internal Link Checker Security & Risk Analysis
wordpress.org/plugins/internal-link-checkerInternal Link Checker
Is Plugin Name: Internal Link Checker Safe to Use in 2026?
Generally Safe
Score 85/100Plugin Name: Internal Link Checker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "internal-link-checker" plugin v0.6.1 exhibits a strong security posture based on the provided static analysis. The complete absence of identified vulnerabilities in its history, coupled with robust code signals like the use of prepared statements for all SQL queries and a capability check for its single file operation, indicates a conscientious development approach. The limited attack surface, with no unprotected AJAX handlers, REST API routes, shortcodes, or cron events, further strengthens its security profile. The lack of any identified taint flows, especially those with unsanitized paths or critical/high severity, is a significant positive indicator. This suggests that user-supplied data is likely handled appropriately and not being exposed to dangerous functions or leading to exploitable conditions. The plugin's history of zero known CVEs, and no recorded common vulnerability types, strongly implies a consistent and secure development track record. While the output escaping is only 50% proper, this is a relatively minor concern given the other strong security measures in place. Overall, this plugin appears to be well-developed and secure, with minimal immediate security risks. The only area for potential improvement is the output escaping, which should ideally be addressed in future updates to achieve a fully secure implementation.
Key Concerns
- 50% of outputs are not properly escaped
Plugin Name: Internal Link Checker Security Vulnerabilities
Plugin Name: Internal Link Checker Code Analysis
SQL Query Safety
Output Escaping
Plugin Name: Internal Link Checker Attack Surface
WordPress Hooks 4
Maintenance & Trust
Plugin Name: Internal Link Checker Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Name: Internal Link Checker Alternatives
Title and Nofollow For Links (Classic Editor)
title-and-nofollow-for-links
The plugin adds a title and a rel="nofollow" checkbox to the insert link popup box. Only for Classic Editor, NOT Block Editor.
Comment Link Suggest-O-Tron
comment-link-suggest-o-tron
What if you could get more comments on your blog?
External Links Modifier
external-links-modifier
External Links Modifier automatically updates external links in your posts to open in a new tab with rel="nofollow noreferrer".
Automatic Domain Changer
automatic-domain-changer
Automatically detects a domain name change, and updates all the WordPress tables in the database to reflect this change.
Custom Meta Widget
custom-meta-widget
Clone of the standard Meta widget plus options to hide log in/out, admin, feed and WordPress.org/custom links.
Plugin Name: Internal Link Checker Developer Profile
1 plugin · 20 total installs
How We Detect Plugin Name: Internal Link Checker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/internal-link-checker/css/style.css/wp-content/plugins/internal-link-checker/js/script.js/wp-content/plugins/internal-link-checker/admin/css/admin.css/wp-content/plugins/internal-link-checker/admin/js/admin.jsInternal links check 0.6.1/wp-content/plugins/internal-link-checker/js/script.js/wp-content/plugins/internal-link-checker/admin/js/admin.jsinternal-link-checker/css/style.css?ver=internal-link-checker/js/script.js?ver=internal-link-checker/admin/css/admin.css?ver=internal-link-checker/admin/js/admin.js?ver=HTML / DOM Fingerprints
ilc-wrapilc-container<!-- start .ilc-wrap -->data-post-idilc_script_vars