Internal Link Flow & Topical Authority & Topical Map Security & Risk Analysis

wordpress.org/plugins/internal-link-flow-topical-authority-topical-map

Visualize and track the internal linking structure of your page using a flow chart. Topical Map and Topical Authority

10 active installs v1.0.1 PHP 7.4+ WP 4.7+ Updated Jan 17, 2023
external-linkflowinternal-linkseotopical-map
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Internal Link Flow & Topical Authority & Topical Map Safe to Use in 2026?

Generally Safe

Score 85/100

Internal Link Flow & Topical Authority & Topical Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "internal-link-flow-topical-authority-topical-map" plugin v1.0.1 exhibits a generally strong security posture based on the static analysis. A notable strength is the complete absence of any identified dangerous functions or file operations, and all identified output is properly escaped, mitigating common web application vulnerabilities. Furthermore, the plugin does not make external HTTP requests, reducing the risk of supply chain attacks. The REST API routes, while present, all appear to have permission callbacks, and there are no unprotected AJAX handlers or shortcodes, which are common entry points for attackers.

The static analysis indicates a cautious approach to SQL queries, with a significant portion utilizing prepared statements, though the remaining percentage are not explicitly detailed as either prepared or not. The lack of any identified taint flows, particularly critical or high severity ones, is a very positive sign, suggesting that user input is likely being handled with care. The plugin's vulnerability history is also clean, with no recorded CVEs, which implies either a highly secure development process or a lack of past scrutiny. However, a key concern is the complete absence of nonce checks, which are a fundamental security measure against Cross-Site Request Forgery (CSRF) attacks, especially considering the presence of REST API endpoints.

Overall, the plugin demonstrates good practices in output escaping and limiting direct code execution risks. The absence of historical vulnerabilities is reassuring. However, the missing nonce checks represent a significant oversight that could expose users to CSRF attacks. The slight ambiguity around the preparedness of all SQL queries warrants further investigation but does not currently present a deduction based on the provided data. The bundled Freemius library, while listed, has no version specified, so its potential for outdated vulnerabilities cannot be assessed. The plugin's current security is good but could be improved by addressing the nonce check deficiency.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

Internal Link Flow & Topical Authority & Topical Map Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Internal Link Flow & Topical Authority & Topical Map Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Internal Link Flow & Topical Authority & Topical Map Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
4 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

57% prepared7 total queries

Output Escaping

100% escaped5 total outputs
Attack Surface

Internal Link Flow & Topical Authority & Topical Map Attack Surface

Entry Points8
Unprotected0

REST API Routes 8

GET/wp-json/tailf/v1/listincludes\class_ilf_create_flow_routes.php:21
GET/wp-json/tailf/v1/postsincludes\class_ilf_create_flow_routes.php:27
GET/wp-json/tailf/v1/createincludes\class_ilf_create_flow_routes.php:33
GET/wp-json/tailf/v1/updateincludes\class_ilf_create_flow_routes.php:39
GET/wp-json/tailf/v1/delete/(?P<id>\d+)includes\class_ilf_create_flow_routes.php:45
GET/wp-json/tailf/v1/edit/(?P<id>\d+)includes\class_ilf_create_flow_routes.php:52
GET/wp-json/tailf/v1/flow/(?P<id>\d+)includes\class_ilf_create_flow_routes.php:59
GET/wp-json/tailf/v1/testincludes\class_ilf_create_flow_routes.php:64
WordPress Hooks 4
actionadmin_menuincludes\class_ilf_create_admin_menu.php:8
actionrest_api_initincludes\class_ilf_create_flow_routes.php:15
actionadmin_enqueue_scriptsinternal-link-flow.php:104
actioninitinternal-link-flow.php:119
Maintenance & Trust

Internal Link Flow & Topical Authority & Topical Map Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedJan 17, 2023
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Internal Link Flow & Topical Authority & Topical Map Developer Profile

Nurullah SERT

2 plugins · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Internal Link Flow & Topical Authority & Topical Map

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/internal-link-flow-topical-authority-topical-map/build/index.css/wp-content/plugins/internal-link-flow-topical-authority-topical-map/build/index.js
Version Parameters
internal-link-flow-topical-authority-topical-map/build/index.css?ver=internal-link-flow-topical-authority-topical-map/build/index.js?ver=

HTML / DOM Fingerprints

JS Globals
window.appLocalizervar appLocalizer
REST Endpoints
/wp-json/tailf/v1/list/wp-json/tailf/v1/posts/wp-json/tailf/v1/create/wp-json/tailf/v1/update/wp-json/tailf/v1/delete/(?P<id>\d+)/wp-json/tailf/v1/edit/(?P<id>\d+)/wp-json/tailf/v1/flow/(?P<id>\d+)/wp-json/tailf/v1/test
FAQ

Frequently Asked Questions about Internal Link Flow & Topical Authority & Topical Map