Landing Lion Landing Pages Security & Risk Analysis

wordpress.org/plugins/landing-lion-landing-pages

Landing Lion is the easiest and fastest landing page builder to create landing pages for your brand.

10 active installs v0.4.2 PHP 5.6+ WP 4.1.5+ Updated Jul 9, 2018
a-b-testingab-testingcrolanding-lionsplit-testing
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Landing Lion Landing Pages Safe to Use in 2026?

Generally Safe

Score 85/100

Landing Lion Landing Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'landing-lion-landing-pages' plugin v0.4.2 presents a concerning security posture due to a significant number of unprotected entry points. All five identified AJAX handlers lack any form of authentication or capability checks, making them prime targets for unauthorized access and potential exploitation. Furthermore, the taint analysis revealed two high-severity flows with unsanitized paths, indicating potential for data injection or manipulation if these paths are reached by malicious input.

While the plugin has no recorded vulnerability history, this should not be interpreted as a sign of robust security. The absence of known CVEs could simply mean it hasn't been extensively audited or that vulnerabilities exist but haven't been publicly disclosed. The lack of output escaping for all identified outputs is a significant weakness, potentially leading to cross-site scripting (XSS) vulnerabilities. The limited use of prepared statements for SQL queries also increases the risk of SQL injection attacks.

Key Concerns

  • All AJAX handlers lack authentication checks
  • High severity taint flows with unsanitized paths
  • No output escaping
  • Low percentage of SQL queries using prepared statements
  • No nonce checks on AJAX handlers
  • No capability checks on AJAX handlers
Vulnerabilities
None known

Landing Lion Landing Pages Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Landing Lion Landing Pages Code Analysis

Dangerous Functions
0
Raw SQL Queries
14
3 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

18% prepared17 total queries

Output Escaping

0% escaped1 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ProxyUrl (landing-lion-wpp.php:57)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

Landing Lion Landing Pages Attack Surface

Entry Points5
Unprotected5

AJAX Handlers 5

authwp_ajax_ll_create_page_mappingApp\Views\LLSettingsPage.php:59
authwp_ajax_ll_update_page_mappingApp\Views\LLSettingsPage.php:78
authwp_ajax_ll_delete_page_mappingApp\Views\LLSettingsPage.php:97
authwp_ajax_get_ll_page_mappingsApp\Views\LLSettingsPage.php:105
authwp_ajax_get_wordpress_page_slugsApp\Views\LLSettingsPage.php:112
WordPress Hooks 7
actionadmin_menuApp\Views\LLSettingsPage.php:36
actionadmin_enqueue_scriptsApp\Views\LLSettingsPage.php:120
actionadmin_enqueue_scriptsApp\Views\LLSettingsPage.php:139
actioninitlanding-lion-wpp.php:51
actionbefore_delete_postlanding-lion-wpp.php:52
actionwp_trash_postlanding-lion-wpp.php:53
actionsave_postlanding-lion-wpp.php:54
Maintenance & Trust

Landing Lion Landing Pages Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedJul 9, 2018
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Landing Lion Landing Pages Developer Profile

craigrmccown

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Landing Lion Landing Pages

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/landing-lion-landing-pages/Assets/css/landing-lion.css/wp-content/plugins/landing-lion-landing-pages/Assets/js/landing-lion.js
Script Paths
/wp-content/plugins/landing-lion-landing-pages/Assets/js/landing-lion.js
Version Parameters
landing-lion-landing-pages/Assets/css/landing-lion.css?ver=landing-lion-landing-pages/Assets/js/landing-lion.js?ver=

HTML / DOM Fingerprints

CSS Classes
ll-settings-page
HTML Comments
<!-- Landing Lion Plugin Options -->
Data Attributes
data-ll-page-iddata-ll-page-url
JS Globals
window.ll_ajax_object
Shortcode Output
[landing_lion_page]
FAQ

Frequently Asked Questions about Landing Lion Landing Pages