LinkGreen Site Integrations Security & Risk Analysis

wordpress.org/plugins/linkgreen-site-integrations

The official LinkGreen plugin. Allows sellers on the LinkGreen platform to display items in a carousel using shortcodes.

0 active installs v1.4.4 PHP + WP 3.0.2+ Updated Jul 12, 2019
apicarousellink-greenlinkgreen
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LinkGreen Site Integrations Safe to Use in 2026?

Generally Safe

Score 85/100

LinkGreen Site Integrations has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "linkgreen-site-integrations" plugin v1.4.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively. Furthermore, it has no recorded vulnerabilities (CVEs), suggesting a history of stable and secure development. However, several concerning aspects warrant attention. The plugin has a notable attack surface with one unprotected AJAX handler, presenting a direct entry point for potential attackers. The taint analysis reveals two flows with unsanitized paths, which, while not classified as critical or high severity in this analysis, still represent a risk of unintended data manipulation or execution if exploited.

The static analysis also indicates that a significant portion of output (41%) is not properly escaped. This can lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being rendered. The absence of nonce checks on the unprotected AJAX handler is a critical omission that exacerbates the risk. While the plugin's vulnerability history is clean, this does not negate the immediate risks identified in the code. The overall security is compromised by the presence of an unprotected AJAX endpoint and potential for XSS due to insufficient output escaping, despite strengths in SQL handling and lack of historical CVEs.

Key Concerns

  • Unprotected AJAX handler present
  • Flows with unsanitized paths
  • Insufficient output escaping (41%)
  • No nonce checks on AJAX handler
Vulnerabilities
None known

LinkGreen Site Integrations Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LinkGreen Site Integrations Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
65
94 escaped
Nonce Checks
0
Capability Checks
1
File Operations
4
External Requests
2
Bundled Libraries
0

Output Escaping

59% escaped159 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
linkgreen_site_integrations_options_page (inc\options-page.php:6)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

LinkGreen Site Integrations Attack Surface

Entry Points4
Unprotected1

AJAX Handlers 1

authwp_ajax_linkgreen_site_refresh_apiinc\refresh-api.php:22

Shortcodes 3

[linkgreen_button] inc\shortcode\buttons.php:43
[linkgreen_carousel] inc\shortcode\carousels.php:80
[linkgreen_section] inc\shortcode\sections.php:45
WordPress Hooks 4
actionwp_headinc\enable-front-end-ajax.php:13
actionadmin_menulinkgreen-site-integrations.php:28
actionadmin_enqueue_scriptslinkgreen-site-integrations.php:40
actionwp_enqueue_scriptslinkgreen-site-integrations.php:50
Maintenance & Trust

LinkGreen Site Integrations Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJul 12, 2019
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LinkGreen Site Integrations Developer Profile

linkgreen

2 plugins · 0 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LinkGreen Site Integrations

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/linkgreen-site-integrations/public/js/app.js/wp-content/plugins/linkgreen-site-integrations/public/css/admin.css/wp-content/plugins/linkgreen-site-integrations/public/css/app.css/wp-content/plugins/linkgreen-site-integrations/public/css/font-awesome.min.css/wp-content/plugins/linkgreen-site-integrations/public/js/gallery.js/wp-content/plugins/linkgreen-site-integrations/public/js/owl.carousel.min.js
Script Paths
/wp-content/plugins/linkgreen-site-integrations/public/js/app.js/wp-content/plugins/linkgreen-site-integrations/public/js/gallery.js/wp-content/plugins/linkgreen-site-integrations/public/js/owl.carousel.min.js

HTML / DOM Fingerprints

JS Globals
ajaxurl
Shortcode Output
[linkgreen_button[linkgreen_carousel[linkgreen_section
FAQ

Frequently Asked Questions about LinkGreen Site Integrations