
Link Footnotes Security & Risk Analysis
wordpress.org/plugins/link-footnotesAdds a footnotes section to your posts with any external links
Is Link Footnotes Safe to Use in 2026?
Generally Safe
Score 85/100Link Footnotes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "link-footnotes" plugin version 0.1.7 exhibits a generally positive security posture based on the provided static analysis. The absence of any known CVEs and a clean vulnerability history suggest a history of responsible development and maintenance. Furthermore, the static analysis reveals no identified vulnerabilities such as dangerous functions, SQL injection risks (all SQL queries use prepared statements), or insecure file operations. The plugin also has a zero attack surface concerning AJAX handlers, REST API routes, and shortcodes, indicating a deliberate effort to limit potential entry points for attackers.
However, a significant concern arises from the output escaping signals. With 3 total outputs and 0% properly escaped, this presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed to users that is not properly sanitized before output could be manipulated by an attacker to inject malicious scripts. The lack of capability checks and nonce checks, while not directly flagged as vulnerabilities due to the zero attack surface, could become risks if the attack surface were to expand in future versions or if specific functionalities were added without proper security controls.
In conclusion, while the plugin has strong foundations with no known vulnerabilities and a minimal attack surface, the complete lack of output escaping is a critical weakness that needs immediate attention. This single oversight significantly elevates the risk profile of the plugin, despite its otherwise clean record and good practices in other areas.
Key Concerns
- Outputs not properly escaped
Link Footnotes Security Vulnerabilities
Link Footnotes Code Analysis
Output Escaping
Link Footnotes Attack Surface
WordPress Hooks 3
Maintenance & Trust
Link Footnotes Maintenance & Trust
Maintenance Signals
Community Trust
Link Footnotes Alternatives
RaraTheme Companion
raratheme-companion
23 extremely useful custom widgets to create an engaging website.
Simple Post Type Permalinks
simple-post-type-permalinks
Easy to change Permalink of custom post type.
No External Links
mihdan-no-external-links
Convert external links into internal links, site wide or post/page specific. Add NoFollow, Click logging, and more...
Admin Collapse Subpages
admin-collapse-subpages
Using this plugin one can easily collapse/expand pages with children and grand children.
Custom Post Type Rewrite
custom-post-type-rewrite
Custom Post Type Rewrite plugin adds default custom post type permalinks.
Link Footnotes Developer Profile
4 plugins · 550 total installs
How We Detect Link Footnotes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
lf_wrapper<div class="lf_wrapper"><h2>Links</h2><ul><div class="lf_wrapper"><h2></h2><ul>