
Link Whisper Free Security & Risk Analysis
wordpress.org/plugins/link-whisperThe AI-powered internal linking plugin for WordPress. Build internal links faster, find linking opportunities, and improve SEO automatically.
Is Link Whisper Free Safe to Use in 2026?
Use With Caution
Score 62/100Link Whisper Free has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "link-whisper" plugin, version 0.9.2, presents a mixed security posture. While it demonstrates some good practices like a significant number of capability checks and a moderate adoption of prepared statements for SQL queries, there are substantial concerns.
The static analysis reveals a very large attack surface, with 93 AJAX handlers, a concerning 79 of which lack authentication checks. This opens the door to numerous potential unauthorized actions. The presence of the `unserialize` function, a known risky operation, coupled with 8 high-severity taint flows with unsanitized paths, indicates a risk of deserialization vulnerabilities and potential for code execution or data manipulation if improperly handled inputs are processed. Furthermore, the output escaping rate of 64% is insufficient, suggesting potential Cross-Site Scripting (XSS) vulnerabilities.
The plugin's vulnerability history is a significant red flag. With 10 known CVEs, including 2 currently unpatched high-severity vulnerabilities, and a history of common types like XSS, Missing Authorization, and SQL Injection, the plugin has a documented pattern of security weaknesses. The last recorded vulnerability in February 2026, while in the future, indicates a recent history of issues. The combination of an exposed attack surface, risky code functions, and a history of critical and high-severity vulnerabilities points to a plugin that requires immediate attention to mitigate significant security risks.
Key Concerns
- Unpatched high severity CVEs
- Large number of AJAX handlers without auth checks
- High severity taint flows with unsanitized paths
- Use of dangerous function: unserialize
- Low output escaping rate
- Multiple medium severity historical CVEs
Link Whisper Free Security Vulnerabilities
CVEs by Year
Severity Breakdown
11 total CVEs
Link Whisper Free < 0.9.1 - Missing Authorization to Unauthenticated Settings Change
Link Whisper Free <= 0.9.2 - Reflected Cross-Site Scripting
Link Whisper Free <= 0.8.8 - Reflected Cross-Site Scripting
Link Whisper Free <= 0.8.8 - Reflected Cross-Site Scripting
Link Whisper Free <= 0.8.8 - Missing Authorization
Link Whisper Free <= 0.7.8 - Unauthenticated Sensitive Information Exposure
Link Whisper Free <= 0.6.9
Link Whisper Free <= 0.7.1 - Authenticated (Contributor+) PHP Object Injection
Link Whisper Free <= 0.6.8 - Reflected Cross-Site Scripting
Link Whisper Free <= 0.6.5 - Authenticated (Contributor+) SQL Injection
Link Whisper Free <= 0.6.3 - Missing Authorization via init()
Link Whisper Free Release Timeline
Link Whisper Free Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Link Whisper Free Attack Surface
AJAX Handlers 93
WordPress Hooks 44
Scheduled Events 7
Maintenance & Trust
Link Whisper Free Maintenance & Trust
Maintenance Signals
Community Trust
Link Whisper Free Alternatives
Interlinks Manager – Internal Links Optimizer
daext-interlinks-manager
Interlinks Manager is an SEO WordPress plugin that gives you the ability to monitor and optimize your internal links.
SEO Links Interlinking
seo-links-interlinking
Automate internal link building in WordPress with Google Search Console. Improve SEO with intelligent interlinking.
Ozi Internal Link Booster — Smart Internal Linking for SEO
ozi-internal-link-booster
Smart, SEO-safe internal linking with keyword mapping, orphan page detection, and lightweight automation. No bloat. No risk.
Internal Links Manager
seo-automated-link-building
Boost your SEO and get better rankings with our automated link building plugin. With this plugin you can link any keyword to any URL - internal or ext …
Autolinks Manager – SEO Auto Linker
daext-autolinks-manager
Automate your affiliate links, increase product page visits, link glossary keywords, and more with this advanced SEO auto-linker plugin.
Link Whisper Free Developer Profile
1 plugin · 30K total installs
How We Detect Link Whisper Free
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/link-whisper/core/Assets/css/main.css/wp-content/plugins/link-whisper/core/Assets/css/vue-multiselect.css/wp-content/plugins/link-whisper/core/Assets/js/vendors/lodash.min.js/wp-content/plugins/link-whisper/core/Assets/js/vendors/vue.js/wp-content/plugins/link-whisper/core/Assets/js/vendors/vue-multiselect.min.js/wp-content/plugins/link-whisper/core/Assets/js/vendors/vuex.min.js/wp-content/plugins/link-whisper/core/Assets/js/helpers/vue_app.js/wp-content/plugins/link-whisper/core/Assets/js/helpers/axios.js+8 more/wp-content/plugins/link-whisper/core/Assets/js/vendors/lodash.min.js/wp-content/plugins/link-whisper/core/Assets/js/vendors/vue.js/wp-content/plugins/link-whisper/core/Assets/js/vendors/vue-multiselect.min.js/wp-content/plugins/link-whisper/core/Assets/js/vendors/vuex.min.js/wp-content/plugins/link-whisper/core/Assets/js/helpers/vue_app.js/wp-content/plugins/link-whisper/core/Assets/js/helpers/axios.js+7 morelink-whisper/core/Assets/css/main.css?ver=link-whisper/core/Assets/css/vue-multiselect.css?ver=link-whisper/core/Assets/js/vendors/lodash.min.js?ver=link-whisper/core/Assets/js/vendors/vue.js?ver=link-whisper/core/Assets/js/vendors/vue-multiselect.min.js?ver=link-whisper/core/Assets/js/vendors/vuex.min.js?ver=link-whisper/core/Assets/js/helpers/vue_app.js?ver=link-whisper/core/Assets/js/helpers/axios.js?ver=link-whisper/core/Assets/js/link-whisper-backend.js?ver=link-whisper/core/Assets/js/link-whisper-frontend.js?ver=link-whisper/core/Assets/js/link-whisper-suggestions.js?ver=link-whisper/core/Assets/js/link-whisper-links.js?ver=link-whisper/core/Assets/js/link-whisper-reporting.js?ver=link-whisper/core/Assets/js/link-whisper-dashboard.js?ver=link-whisper/core/Assets/js/link-whisper-settings.js?ver=HTML / DOM Fingerprints
wpil_link_suggestions_wrapperwpil_suggestions_titlewpil_new_suggestion_buttonwpil_suggestions_tablewpil_suggestion_rowwpil_suggestion_actionswpil_suggestions_action_buttonswpil_add_link_button+44 more<!-- Wpil_Init::register_services() --><!-- Check if the premium version is installed --><!-- autoloader --><!-- Main plugin file -->+76 moredata-wpil-post-typedata-wpil-post-iddata-wpil-suggestion-iddata-wpil-editor-iddata-wpil-target-urldata-wpil-link-text+4 morewpil_varsWpillodashVueVueMultiselectVuex+1 more