Linkbuildr Security & Risk Analysis

wordpress.org/plugins/linkbuildr

Automated content promotion. Share your content with the people who care the most, automatically.

20 active installs v1.3 PHP 5.3+ WP 5.2+ Updated Jan 14, 2020
automationcontent-promotionoutreachoutreach-automation
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Linkbuildr Safe to Use in 2026?

Generally Safe

Score 85/100

Linkbuildr has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'linkbuildr' v1.3 plugin exhibits a generally positive security posture based on the static analysis. It demonstrates good practices by avoiding dangerous functions, file operations, and external HTTP requests. The high percentage of SQL queries using prepared statements and properly escaped outputs are significant strengths. The presence of numerous nonce and capability checks further indicates an effort to secure its functionalities. However, the taint analysis reveals a potential concern with one flow containing an unsanitized path. While this is rated as high severity and not critical, it warrants attention as it could potentially lead to issues if exploited. The plugin's vulnerability history is clean, with no recorded CVEs, which is a strong indicator of its current stability and lack of previously discovered widespread vulnerabilities. Overall, 'linkbuildr' v1.3 appears to be a secure plugin with a focus on defensive coding, but the single high-severity taint flow requires investigation to ensure it doesn't pose a real-world risk.

Key Concerns

  • Flow with unsanitized path (high severity)
Vulnerabilities
None known

Linkbuildr Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Linkbuildr Code Analysis

Dangerous Functions
0
Raw SQL Queries
15
76 prepared
Unescaped Output
33
231 escaped
Nonce Checks
14
Capability Checks
20
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

84% prepared91 total queries

Output Escaping

88% escaped264 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

11 flows1 with unsanitized paths
process_bulk_action (classes\class-linkbuildr-email-templates-table.php:186)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Linkbuildr Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 28
actionrest_api_initclasses\class-linkbuildr-api.php:92
actioninitclasses\class-linkbuildr-events.php:106
actioninitclasses\class-linkbuildr-events.php:107
actioninitclasses\class-linkbuildr-events.php:108
actionwpclasses\class-linkbuildr-events.php:109
actionpublish_postclasses\class-linkbuildr-events.php:111
actiondraft_postclasses\class-linkbuildr-events.php:112
actionwp_insert_postclasses\class-linkbuildr-events.php:114
actionpost_submitbox_misc_actionsclasses\class-linkbuildr-events.php:116
actionenqueue_block_editor_assetsclasses\class-linkbuildr-events.php:118
actionadmin_enqueue_scriptsclasses\class-linkbuildr-events.php:119
filterthe_contentclasses\class-linkbuildr-events.php:121
actionwpmu_new_blogclasses\class-linkbuildr-migration.php:215
actioninitclasses\class-linkbuildr-migration.php:216
actionadmin_menuclasses\class-linkbuildr-settings.php:139
actionadmin_initclasses\class-linkbuildr-settings.php:140
actioninitclasses\class-linkbuildr-settings.php:141
actionplugins_loadedclasses\class-linkbuildr.php:201
actionwp_enqueue_scriptsclasses\class-linkbuildr.php:202
actionadmin_enqueue_scriptsclasses\class-linkbuildr.php:203
actionadmin_enqueue_scriptsclasses\class-linkbuildr.php:204
actionwpmu_new_blogclasses\class-linkbuildr.php:206
actionadmin_noticesclasses\class-linkbuildr.php:208
actioninitclasses\class-linkbuildr.php:210
actioninitincludes\admin-notice-helper\admin-notice-helper.php:44
actionadmin_noticesincludes\admin-notice-helper\admin-notice-helper.php:45
actionshutdownincludes\admin-notice-helper\admin-notice-helper.php:46
actionadmin_noticeslinkbuildr.php:75
Maintenance & Trust

Linkbuildr Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedJan 14, 2020
PHP min version5.3
Downloads4K

Community Trust

Rating92/100
Number of ratings11
Active installs20
Developer Profile

Linkbuildr Developer Profile

FTF Developer

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Linkbuildr

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/linkbuildr/assets/css/linkbuildr-admin-settings.css/wp-content/plugins/linkbuildr/assets/js/linkbuildr-admin-settings.js/wp-content/plugins/linkbuildr/assets/js/linkbuildr-block-editor.js/wp-content/plugins/linkbuildr/assets/js/linkbuildr-block-preview.js/wp-content/plugins/linkbuildr/assets/js/linkbuildr-unsubscribe.js
Script Paths
/wp-content/plugins/linkbuildr/assets/js/linkbuildr-admin-settings.js/wp-content/plugins/linkbuildr/assets/js/linkbuildr-block-editor.js/wp-content/plugins/linkbuildr/assets/js/linkbuildr-block-preview.js/wp-content/plugins/linkbuildr/assets/js/linkbuildr-unsubscribe.js
Version Parameters
linkbuildr/assets/css/linkbuildr-admin-settings.css?ver=linkbuildr/assets/js/linkbuildr-admin-settings.js?ver=linkbuildr/assets/js/linkbuildr-block-editor.js?ver=linkbuildr/assets/js/linkbuildr-block-preview.js?ver=linkbuildr/assets/js/linkbuildr-unsubscribe.js?ver=

HTML / DOM Fingerprints

CSS Classes
linkbuildr-admin-settings-pagelinkbuildr-block-preview-wrapperlinkbuildr-unsubscribe-messagelinkbuildr-admin-settings-fieldlinkbuildr-admin-settings-inputlinkbuildr-admin-settings-textarealinkbuildr-admin-settings-selectlinkbuildr-admin-settings-checkbox+1 more
HTML Comments
<!-- Linkbuildr: Linkbuildr_Events class --><!-- Linkbuildr: Linkbuildr_Settings class --><!-- Linkbuildr: Linkbuildr_Migration class --><!-- Linkbuildr: Linkbuildr_API class -->+4 more
Data Attributes
data-linkbuildr-block-previewdata-linkbuildr-unsubscribe-token
JS Globals
linkbuildrSettingslinkbuildrBlockPreviewLinkbuildrUnsubscribe
REST Endpoints
/wp-json/linkbuildr/v1/settings/wp-json/linkbuildr/v1/contacts/wp-json/linkbuildr/v1/links
Shortcode Output
[linkbuildr_promo_box][linkbuildr_unsubscribe_link]
FAQ

Frequently Asked Questions about Linkbuildr