Link Juice Optimizer Security & Risk Analysis

wordpress.org/plugins/link-juice-optimizer

Replace links with a clickable <span> tag, add the nofollow attribute or remove the href attribute to optimize link juice.

6K active installs v2.3.2 PHP 5.6.39+ WP 5.0+ Updated Jan 16, 2024
crawl-budgetinternal-linkinglink-juiceobfuscation
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Link Juice Optimizer Safe to Use in 2026?

Generally Safe

Score 85/100

Link Juice Optimizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "link-juice-optimizer" v2.3.2 plugin exhibits a very strong security posture based on the provided static analysis and vulnerability history. The absence of any identified entry points, dangerous functions, raw SQL queries, file operations, external HTTP requests, or taint flows is highly commendable and suggests a robust, secure coding approach. The high percentage of properly escaped output further reinforces this positive assessment, indicating a good understanding of preventing cross-site scripting (XSS) vulnerabilities.

Furthermore, the complete lack of known CVEs, both historically and currently unpatched, is an exceptional indicator of security maturity. This suggests that the plugin has either been meticulously developed without introducing common vulnerabilities or has had any potential issues promptly addressed. The absence of recorded common vulnerability types also contributes to a low-risk profile.

While the plugin demonstrates excellent security practices, the lack of any identified attack surface (AJAX, REST API, shortcodes, cron events) is an unusual observation. If the plugin's intended functionality requires any of these, their absence might indicate a limited scope or that functionality is handled elsewhere. However, based solely on the provided data, the plugin appears to be highly secure with no immediate exploitable risks.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Link Juice Optimizer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Link Juice Optimizer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
38 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

84% escaped45 total outputs
Attack Surface

Link Juice Optimizer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 22
actionplugins_loadedincludes\class-link-juice-optimizer.php:143
actionadmin_enqueue_scriptsincludes\class-link-juice-optimizer.php:157
filterin_widget_formincludes\class-link-juice-optimizer.php:159
filterwidget_update_callbackincludes\class-link-juice-optimizer.php:160
actionafter_wp_tiny_mceincludes\class-link-juice-optimizer.php:162
actionafter_setup_themeincludes\class-link-juice-optimizer.php:164
actioncarbon_fields_register_fieldsincludes\class-link-juice-optimizer.php:165
actionwp_enqueue_scriptsincludes\class-link-juice-optimizer.php:182
filterthe_contentincludes\class-link-juice-optimizer.php:184
filterdynamic_sidebar_paramsincludes\class-link-juice-optimizer.php:185
filterwidget_outputincludes\class-link-juice-optimizer.php:186
filterwalker_nav_menu_start_elincludes\class-link-juice-optimizer.php:187
actionelementor/widget/render_contentincludes\class-link-juice-optimizer.php:189
actionwp_headincludes\class-link-juice-optimizer.php:191
actionplugins_loadedincludes\class-link-juice-optimizer.php:192
filterwoocommerce_loop_add_to_cart_linkincludes\class-link-juice-optimizer.php:194
actionwp_headincludes\class-link-juice-optimizer.php:199
actionwp_footerincludes\class-link-juice-optimizer.php:200
actionwoocommerce_before_shop_loop_itempublic\class-link-juice-optimizer-public.php:575
actionwoocommerce_after_shop_loop_itempublic\class-link-juice-optimizer-public.php:577
actionwoocommerce_before_subcategorypublic\class-link-juice-optimizer-public.php:581
actionwoocommerce_after_subcategorypublic\class-link-juice-optimizer-public.php:583
Maintenance & Trust

Link Juice Optimizer Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedJan 16, 2024
PHP min version5.6.39
Downloads22K

Community Trust

Rating100/100
Number of ratings4
Active installs6K
Developer Profile

Link Juice Optimizer Developer Profile

Fede Gómez

2 plugins · 6K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Link Juice Optimizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/link-juice-optimizer/admin/css/link-juice-optimizer-admin.css/wp-content/plugins/link-juice-optimizer/public/css/link-juice-optimizer.css/wp-content/plugins/link-juice-optimizer/public/js/link-juice-optimizer.js
Script Paths
/wp-content/plugins/link-juice-optimizer/public/js/link-juice-optimizer.js
Version Parameters
link-juice-optimizer/css/link-juice-optimizer-admin.css?ver=link-juice-optimizer/css/link-juice-optimizer.css?ver=link-juice-optimizer/js/link-juice-optimizer.js?ver=

HTML / DOM Fingerprints

CSS Classes
ljoptimizer
FAQ

Frequently Asked Questions about Link Juice Optimizer