
Link View Security & Risk Analysis
wordpress.org/plugins/link-viewDisplay a link-list or link-slider in a post or page by using a shortcode.
Is Link View Safe to Use in 2026?
High Risk
Score 42/100Link View carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The 'link-view' plugin v0.8.0 exhibits a mixed security posture. On the positive side, static analysis reveals excellent practices with 100% of SQL queries using prepared statements and a very high percentage (98%) of output escaping. The attack surface is minimal, with only one shortcode and no unprotected entry points from AJAX, REST API, or cron events. There are also capability checks present in the code.
However, significant concerns arise from the plugin's vulnerability history. With two known CVEs, both currently unpatched and classified as medium severity, this indicates a recurring pattern of potential vulnerabilities. The common vulnerability type being Cross-site Scripting (XSS) suggests that user-supplied data might not always be handled securely, despite the generally good output escaping observed in static analysis. The presence of these unpatched vulnerabilities is the most critical risk factor.
In conclusion, while the code itself appears to follow many good security practices, the existence of two unpatched medium severity vulnerabilities, specifically XSS, is a substantial risk. The plugin's developers need to address these known issues promptly. Users should be aware that despite the static analysis results showing good code hygiene, the historical data points to a past need for more robust input validation and output sanitization that may not have been fully addressed.
Key Concerns
- Unpatched CVE (Medium severity)
- Unpatched CVE (Medium severity)
- 0 Nonce checks present
Link View Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Link View <= 0.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Link View <= 0.8.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Link View Code Analysis
Output Escaping
Data Flow Analysis
Link View Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Link View Maintenance & Trust
Maintenance Signals
Community Trust
Link View Alternatives
Link Manager
link-manager
Enables the Link Manager that existed in WordPress until version 3.5.
Display All Image Sizes
display-all-image-sizes
Displays all sizes of each image, including name, dimensions, and permalink for each size.
Eazy Enable Blogroll
eazy-enable-blogroll
Eazy Enable Blogroll brings back the one and only WordPress Blogroll Feature, with nearly one click!
Blogroll Links
blogroll-links
Display your blogroll links anywhere in posts or pages using a simple shortcode.
Blogroll Widget with RSS Feeds
blogroll-rss-widget
Displays the recent posts of your blogroll links via RSS Feeds in a customizable sidebar widget
Link View Developer Profile
1 plugin · 800 total installs
How We Detect Link View
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/link-view/admin/css/about.css/wp-content/plugins/link-view/admin/css/settings.css/wp-content/plugins/link-view/includes/js/easySlider.min.js/wp-content/plugins/link-view/includes/js/masonry.pkgd.min.js/wp-content/plugins/link-view/includes/js/easySlider.min.js/wp-content/plugins/link-view/includes/js/masonry.pkgd.min.jslink-view/admin/css/about.css?ver=link-view/admin/css/settings.css?ver=link-view/includes/js/easySlider.min.js?ver=link-view/includes/js/masonry.pkgd.min.js?ver=HTML / DOM Fingerprints
data-lvw-sliderdata-lvw-slider-options[linkview