Plugin name: JD Link Exchange Security & Risk Analysis

wordpress.org/plugins/jd-link-exchange

Your Ultimate Resource For SEO Link Exchange

10 active installs v1.3 PHP + WP 3.0.1+ Updated Unknown
exchangelinklink-exchangewidgetwidget-link
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Plugin name: JD Link Exchange Safe to Use in 2026?

Generally Safe

Score 100/100

Plugin name: JD Link Exchange has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "jd-link-exchange" v1.3 plugin exhibits a generally good security posture with no known vulnerabilities or critical code signals like dangerous functions or raw SQL queries. The absence of external HTTP requests and file operations is also positive. However, several areas require attention. The low percentage of properly escaped output (34%) suggests a significant risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data might be rendered directly in the browser without adequate sanitization. Furthermore, the presence of a taint flow with unsanitized paths, while not reaching critical or high severity in the static analysis, indicates a potential avenue for data manipulation if not handled carefully within the shortcode implementation. The complete lack of nonce and capability checks across all entry points, including the shortcode, is a significant concern, as it allows any user, regardless of their role or authentication status, to trigger the shortcode's functionality. While the overall vulnerability history is clean, the identified code signals point to potential weaknesses that could be exploited in the absence of robust input validation and output escaping.

Key Concerns

  • Low output escaping percentage
  • Taint flow with unsanitized paths
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Plugin name: JD Link Exchange Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Plugin name: JD Link Exchange Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

34% escaped35 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<index> (index.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Plugin name: JD Link Exchange Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[jd-links] jd-link-exchange.php:62
WordPress Hooks 3
actionadmin_menujd-link-exchange.php:52
actioninitjd-link-exchange.php:59
actionwidgets_initwidget.php:118
Maintenance & Trust

Plugin name: JD Link Exchange Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Plugin name: JD Link Exchange Developer Profile

Jooky

2 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Plugin name: JD Link Exchange

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jd-link-exchange/assets/icon-24x24.png/wp-content/plugins/jd-link-exchange/assets/icon-96x96.png

HTML / DOM Fingerprints

Shortcode Output
<ul><li><a href="http://www.jd-link.net" title="Free backlink" target="_blank">Add link</a></li></ul><li>
FAQ

Frequently Asked Questions about Plugin name: JD Link Exchange