
Linker – URL shortener & track outbound link clicks Security & Risk Analysis
wordpress.org/plugins/linkerTrack Outbound Link Clicks Easily: Shorten & track your site links by using your own domain name. e.g. "your-domain.com/go/link"
Is Linker – URL shortener & track outbound link clicks Safe to Use in 2026?
Generally Safe
Score 92/100Linker – URL shortener & track outbound link clicks has a strong security track record. Known vulnerabilities have been patched promptly.
The "linker" plugin v1.3.0 demonstrates several positive security practices, including the absence of direct SQL queries without prepared statements and the presence of nonce checks. The static analysis shows a clean slate regarding dangerous functions, file operations, and external HTTP requests. However, there are notable areas for concern. A significant portion of output (32%) is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities, especially given that the plugin's history includes an XSS vulnerability. The taint analysis revealing a flow with unsanitized paths, even if not classified as critical or high severity, warrants attention as it indicates potential weaknesses in input handling. The fact that there is one known CVE, although currently patched, and a history of XSS vulnerabilities suggests a pattern that requires vigilance. While the current version appears to have addressed past issues and exhibits good practices in some areas, the unescaped output and the taint flow highlight potential risks that could be exploited if not carefully managed.
Key Concerns
- Significant unescaped output detected
- Taint flow with unsanitized paths
- Known past vulnerability (XSS)
Linker – URL shortener & track outbound link clicks Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Linker <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Linker – URL shortener & track outbound link clicks Code Analysis
Output Escaping
Data Flow Analysis
Linker – URL shortener & track outbound link clicks Attack Surface
WordPress Hooks 11
Maintenance & Trust
Linker – URL shortener & track outbound link clicks Maintenance & Trust
Maintenance Signals
Community Trust
Linker – URL shortener & track outbound link clicks Alternatives
Linkt – A Plugin for Affiliate Links, Branded Links and Custom Link Tracking & Management
linkt
Simplify your affiliate link management and tracking with Linkt, the ultimate WordPress plugin for creating, categorizing, and analyzing your website …
WP 301 Redirects by WPBranch
redirects-for-wp
WP 301 Redirects is easy to use, and provides an easy method for redirecting requests to another page on your site or elsewhere on the web.
Simple 301 Redirects By BetterLinks – Easy WordPress Redirect Manager for Redirects, 404 Error Log & More
simple-301-redirects
Simple 301 Redirects provides an easy method of redirecting requests to another page on your site or elsewhere on the web.
PublishPress Shortlinks – Custom URLs for Posts and External Links – Share Previews for Draft Posts
tinypress
Create custom links for your posts. These links are brandable, trackable, and can have custom view permissions.
Edge Link Router
edge-link-router
Simple redirect management with optional Cloudflare edge acceleration. Create short links, track clicks, add UTM parameters.
Linker – URL shortener & track outbound link clicks Developer Profile
15 plugins · 13.2M total installs
How We Detect Linker – URL shortener & track outbound link clicks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/linker/assets/css/admin-linker.css/wp-content/plugins/linker/assets/js/admin-linker.jslinker/assets/css/admin-linker.css?ver=linker/assets/js/admin-linker.js?ver=HTML / DOM Fingerprints
linker-permalink-copy-paste<!-- Don't forward - Do not include URL parameters from the referrer when redirecting. --><!-- Forward & Override - Forward URL parameters while replacing existing ones in the destinat --><!-- Forward Without Overriding - Forward URL parameters without replacing existing ones in the destination URL. -->id="linker-url-information"