
Link Away Security & Risk Analysis
wordpress.org/plugins/link-awayLink Away makes it easy to replace a post's permalink with any URL you choose on a post by post basis.
Is Link Away Safe to Use in 2026?
Generally Safe
Score 85/100Link Away has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "link-away" v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin has no known historical vulnerabilities (CVEs), and its code analysis reveals a complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests. It also correctly utilizes prepared statements for its SQL queries and includes nonce and capability checks, which are good security practices for WordPress plugins.
However, a significant concern arises from the output escaping. With 31 total outputs and 0% properly escaped, this represents a critical weakness. This lack of proper output escaping makes the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. Any data rendered to the user interface that originates from potentially untrusted sources could be exploited to inject malicious scripts. The absence of any taint analysis flows being analyzed or found is also noted, but this could be due to the analysis tooling or the plugin's limited functionality rather than an inherent security strength.
In conclusion, while the "link-away" plugin avoids common pitfalls like raw SQL and dangerous functions, its failure to properly escape output for display creates a substantial XSS risk. The lack of historical vulnerabilities is a positive sign, but it doesn't mitigate the immediate danger posed by the unescaped output. The plugin's overall security is significantly compromised by this deficiency.
Key Concerns
- 0% of outputs properly escaped
Link Away Security Vulnerabilities
Link Away Code Analysis
Output Escaping
Link Away Attack Surface
WordPress Hooks 4
Maintenance & Trust
Link Away Maintenance & Trust
Maintenance Signals
Community Trust
Link Away Alternatives
WP-Parsi Permalink Translator
wp-parsi-permalink-translator
Automatic translate post title for use as slug
Disable Title Links
disable-title-links
Disables post and page title links site-wide, showing titles as plain text without clicks, underlines, or page reloads.
Post title link
post-title-custom-link
Use to add custom link for post title.
Custom Post Type Permalinks
custom-post-type-permalinks
Edit the permalink of custom post type.
Custom Permalinks
custom-permalinks
A powerful WordPress plugin for full URL control. Set custom permalinks, auto-redirects, and use dynamic tags for ideal site structure and SEO.
Link Away Developer Profile
4 plugins · 60 total installs
How We Detect Link Away
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
id="inm_la_title_url"id="inm_la_new"id="inm_la_test_button"value="Test..."window.openURL