Link Widget Title Security & Risk Analysis

wordpress.org/plugins/link-widget-title

This plugin adds an extra field to all widgets that allows you add a link to the widget title.

4K active installs v1.0.2 PHP + WP + Updated Nov 14, 2022
widgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Link Widget Title Safe to Use in 2026?

Generally Safe

Score 85/100

Link Widget Title has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'link-widget-title' plugin version 1.0.2 exhibits a generally strong security posture based on the static analysis provided. There are no identified entry points in the attack surface, and crucially, no unprotected AJAX handlers or REST API routes. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and avoiding file operations or external HTTP requests. However, the low percentage of properly escaped output (9%) is a significant concern. While taint analysis and vulnerability history show no immediate threats, this lack of robust output escaping creates a potential risk for cross-site scripting (XSS) vulnerabilities if any of the plugin's outputs are rendered in the browser without proper sanitization.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Link Widget Title Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Link Widget Title Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

9% escaped11 total outputs
Attack Surface

Link Widget Title Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedincludes\class-link-widget-title.php:142
actionadmin_enqueue_scriptsincludes\class-link-widget-title.php:157
actionadmin_enqueue_scriptsincludes\class-link-widget-title.php:158
actionin_widget_formincludes\class-link-widget-title.php:160
filterwidget_form_callbackincludes\class-link-widget-title.php:161
filterwidget_update_callbackincludes\class-link-widget-title.php:162
filterdynamic_sidebar_paramsincludes\class-link-widget-title.php:163
actionwp_enqueue_scriptsincludes\class-link-widget-title.php:199
actionwp_enqueue_scriptsincludes\class-link-widget-title.php:200
Maintenance & Trust

Link Widget Title Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 14, 2022
PHP min version
Downloads13K

Community Trust

Rating60/100
Number of ratings4
Active installs4K
Developer Profile

Link Widget Title Developer Profile

allurewebsolutions

3 plugins · 4K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Link Widget Title

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/link-widget-title/admin/css/link-widget-title-admin.css/wp-content/plugins/link-widget-title/admin/js/link-widget-title-admin.js
Script Paths
/wp-content/plugins/link-widget-title/admin/js/link-widget-title-admin.js
Version Parameters
link-widget-title-admin.css?ver=link-widget-title-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
title-link-options
Data Attributes
title_linktitle_link_target_blanktitle_link_wrap
FAQ

Frequently Asked Questions about Link Widget Title