Linkedin_Oauth Security & Risk Analysis

wordpress.org/plugins/linkedin-oauth

Linkedin_Oauth allows users to login/register into your wordpress using their linkedin account, uses shortcodes.

10 active installs v0.1.6 PHP + WP 4.0+ Updated Dec 27, 2015
linkedinlinkedin-apilogginoauth2social
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Linkedin_Oauth Safe to Use in 2026?

Generally Safe

Score 85/100

Linkedin_Oauth has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'linkedin-oauth' plugin version 0.1.6 exhibits a generally positive security posture with no known vulnerabilities and a strong adherence to secure coding practices in several key areas. The absence of any critical or high-severity taint flows, alongside the complete avoidance of dangerous functions and raw SQL queries, are significant strengths. The plugin also demonstrates a conscious effort to implement capability checks for its entry points. However, a critical weakness is identified in its output escaping, with a concerning 0% of the 24 identified outputs being properly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or data retrieved from external sources could be rendered directly in the browser without sanitization, allowing attackers to inject malicious scripts.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
Vulnerabilities
None known

Linkedin_Oauth Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Linkedin_Oauth Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped24 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
linkedin_init (linkedin_oauth.php:146)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Linkedin_Oauth Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[linkedinbtn] linkedin_oauth.php:86
WordPress Hooks 6
actionplugins_loadedlinkedin_oauth.php:28
actionadmin_initlinkedin_oauth.php:43
filterlogin_formlinkedin_oauth.php:87
actionadmin_initlinkedin_oauth.php:89
actionadmin_menulinkedin_oauth.php:140
filterwp_setup_nav_menu_itemlinkedin_oauth.php:249
Maintenance & Trust

Linkedin_Oauth Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedDec 27, 2015
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

Linkedin_Oauth Developer Profile

Eric Zeidan

3 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Linkedin_Oauth

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/linkedin-oauth/img/bck_button.png/wp-content/plugins/linkedin-oauth/img/bck_button_en.png

HTML / DOM Fingerprints

CSS Classes
linkedin-oauth-login-pop
Shortcode Output
<div id="linkedin_oauth_btn"><a href="https://www.linkedin.com/uas/oauth2/authorization?response_type=code&client_id=<img src="
FAQ

Frequently Asked Questions about Linkedin_Oauth