
LH Wayback Machine Security & Risk Analysis
wordpress.org/plugins/lh-wayback-machineAutomatically creates Wayback Machine snapshots of site, including archives
Is LH Wayback Machine Safe to Use in 2026?
Generally Safe
Score 85/100LH Wayback Machine has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The lh-wayback-machine plugin v1.03 exhibits a generally strong security posture in several key areas. The static analysis reveals a complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests (other than one that is not detailed). More importantly, the plugin has a clean vulnerability history with zero known CVEs, which is a very positive indicator. This suggests the developers are either very security-conscious or the plugin's functionality is limited enough to not present significant attack vectors. However, the static analysis does highlight a critical concern: 100% of output is not properly escaped. This means that any data displayed by the plugin that originates from user input or external sources could be vulnerable to Cross-Site Scripting (XSS) attacks. While there are no identified taint flows or unsanitized paths in the current analysis, the lack of output escaping creates a potential avenue for attackers if any unsanitized data were to be processed and rendered. The plugin also has no capability checks or nonce checks, which, combined with the lack of directly identifiable entry points in this specific analysis, might suggest a limited interaction model, but it's a practice that should be reviewed for any potential user-facing components.
Key Concerns
- 100% of output unescaped
- No capability checks
- No nonce checks
LH Wayback Machine Security Vulnerabilities
LH Wayback Machine Code Analysis
Output Escaping
LH Wayback Machine Attack Surface
WordPress Hooks 10
Scheduled Events 3
Maintenance & Trust
LH Wayback Machine Maintenance & Trust
Maintenance Signals
Community Trust
LH Wayback Machine Alternatives
Archiveo – Importer for the Wayback Machine
archiveo-importer-wayback
Import archived pages from the Wayback Machine into WordPress as editable drafts.
Internet Archive Wayback Machine Link Fixer
internet-archive-wayback-machine-link-fixer
Automatically fix broken links by replacing them with archived versions from the Internet Archive's Wayback Machine.
Multiple Content Types
multiple-content-types
Easily select which content types (custom post types) you want to display on your main blog and archive pages.
Old Post Notice
old-post-notice
Automatically display a customizable notice on posts older than a set number of days.
SF Archiver
sf-archiver
Add some small and useful utilities for managing your Custom Post Types archives.
LH Wayback Machine Developer Profile
77 plugins · 15K total installs
How We Detect LH Wayback Machine
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lh-wayback-machine/lh-wayback-machine.phpHTML / DOM Fingerprints
data-lh-wayback-machine-timestamplh_wayback_machine_params[lh_wayback_machine_button]