Link Manager Security & Risk Analysis

wordpress.org/plugins/link-manager

Enables the Link Manager that existed in WordPress until version 3.5.

20K active installs v0.1-beta PHP + WP 3.5+ Updated Nov 28, 2017
blogrolllink-managerlinks
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Link Manager Safe to Use in 2026?

Generally Safe

Score 85/100

Link Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'link-manager' plugin, in its current beta state (v0.1-beta), exhibits an excellent security posture based on the provided static analysis. The absence of any identified dangerous functions, direct SQL queries, unescaped output, file operations, external HTTP requests, or taint analysis issues is a strong indicator of well-written and secure code. Furthermore, the complete lack of identified CVEs in its vulnerability history suggests a responsible development process and a low likelihood of known exploitable flaws. The plugin also has zero identified entry points, meaning there is no direct attack surface exposed via AJAX, REST API, shortcodes, or cron events.

Despite the overwhelmingly positive static analysis, the plugin is in beta. This implies that it is still under active development and may not have undergone comprehensive security auditing or real-world testing. While the code itself appears robust, the lack of any capability checks or nonce checks on potential future entry points could become a concern if such points are introduced without proper security measures. The current state is very secure, but the beta status warrants continued vigilance and a review of security implementations as the plugin matures and its attack surface potentially grows.

Key Concerns

  • Beta version, potential for future vulnerabilities
  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Link Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Link Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Link Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterpre_option_link_manager_enabledlink-manager.php:12
Maintenance & Trust

Link Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 28, 2017
PHP min version
Downloads417K

Community Trust

Rating90/100
Number of ratings33
Active installs20K
Developer Profile

Link Manager Developer Profile

Andrew Nacin

6 plugins · 22K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Link Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Link Manager