
Linked Pages Security & Risk Analysis
wordpress.org/plugins/linked-pagesThe Linked Pages plugin allows links between posts to be created using customisable page pickers and then displayed using the built in widget.
Is Linked Pages Safe to Use in 2026?
Generally Safe
Score 85/100Linked Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "linked-pages" plugin version 0.2.3 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with exploitable attack vectors is a significant positive. Furthermore, the plugin demonstrates good practices with a substantial number of capability checks and the presence of nonce checks, indicating an effort to secure its functionality. The limited number of SQL queries and the relatively high percentage using prepared statements is also encouraging, minimizing the risk of SQL injection vulnerabilities.
However, a notable concern arises from the low percentage of properly escaped output (19%). This suggests that a significant portion of the plugin's output may be vulnerable to Cross-Site Scripting (XSS) attacks. While no critical or high severity taint flows were detected, the lack of proper output escaping presents a direct avenue for attackers to inject malicious scripts into the WordPress site. The vulnerability history being entirely clean is a positive indicator of past security diligence, but it doesn't mitigate the immediate risks identified in the static analysis.
In conclusion, while the plugin has a low attack surface and implements some crucial security checks, the widespread lack of output escaping is a significant weakness. This needs to be addressed to prevent potential XSS vulnerabilities. The plugin's clean vulnerability history is commendable, but current code-level issues must be prioritized.
Key Concerns
- Low percentage of properly escaped output
Linked Pages Security Vulnerabilities
Linked Pages Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Linked Pages Attack Surface
WordPress Hooks 4
Maintenance & Trust
Linked Pages Maintenance & Trust
Maintenance Signals
Community Trust
Linked Pages Alternatives
Get Custom Field Values
get-custom-field-values
Use widgets, shortcodes, and/or template tags to easily retrieve and display custom field values for posts or pages.
Ultimate Fields
ultimate-fields
Easy and powerful custom fields management: Post Meta, Options Pages, Repeaters and many field types!
Show Hidden Post Meta
show-hidden-post-meta
Makes hidden post meta visible on post edit screens
WP-Admin Search Post Meta
wp-admin-search-meta
Enables searching post meta fields on admin pages.
Post Meta Viewer
post-meta-viewer
View all post meta that saved in a post, page or custom post type in easily readable format. No settings needed just plug and play.
Linked Pages Developer Profile
3 plugins · 120 total installs
How We Detect Linked Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widefat