
Linkedin Profile Badge Security & Risk Analysis
wordpress.org/plugins/linkedin-profile-badgeThis plugin lets you easily add the Linkedin Profile badge to your WordPress blog via a shortcode.
Is Linkedin Profile Badge Safe to Use in 2026?
Generally Safe
Score 85/100Linkedin Profile Badge has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'linkedin-profile-badge' v1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, raw SQL queries, file operations, and external HTTP requests. The absence of known vulnerabilities in its history is also a strong indicator of a stable codebase. However, there are significant areas of concern. The plugin lacks any nonce or capability checks, meaning that its single entry point, the shortcode, is completely unprotected against unauthorized access or manipulation. Furthermore, a concerningly low 15% of its output is properly escaped, leaving it highly susceptible to Cross-Site Scripting (XSS) vulnerabilities, especially given that the shortcode likely renders user-influenced data. The lack of taint analysis flows is noted, but the presence of unprotected entry points and insufficient output escaping suggests potential vulnerabilities that might not have been captured by that specific analysis.
Key Concerns
- No capability checks
- No nonce checks
- Low output escaping (85% unescaped)
- Unprotected shortcode
Linkedin Profile Badge Security Vulnerabilities
Linkedin Profile Badge Release Timeline
Linkedin Profile Badge Code Analysis
Output Escaping
Linkedin Profile Badge Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Linkedin Profile Badge Maintenance & Trust
Maintenance Signals
Community Trust
Linkedin Profile Badge Alternatives
Structured Content (JSON-LD) #wpsc
structured-content
Add flexible content boxes with JSON-LD microdata output according to schema.org e.g. FAQPage, ProfilePage, Event, Course, LocalBusiness, JobPosting a …
TechGasp Link Master
linkedin-master
TechGasp Link Master, if you are serious about your linkedin connections and want to integrate your personal linkedin page, company follow button and …
Google+ Badge Widget
google-badge-widget
Google+ Badge Widget integrated with Official Google Plus API. Google+ Widget enable users to adds beautiful widget on your Wordpress Blog.
Home Badges
home-badges
Quickly access your Blog and Home page in the Wordpress Admin.
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
Linkedin Profile Badge Developer Profile
13 plugins · 4K total installs
How We Detect Linkedin Profile Badge
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
//platform.linkedin.com/in.jsHTML / DOM Fingerprints
<!-- Linkedin Profile Badge: http://3doordigital.com/wordpress/plugins/linkedin-profile-badge/ -->data-relateddata-textdata-iddata-format<script type="IN/MemberProfile"