
Links shortcode Security & Risk Analysis
wordpress.org/plugins/links-shortcodeThe plugin provides the shortcode 'links'. This shortcode shows all links having specified characteristics, following a specified template.
Is Links shortcode Safe to Use in 2026?
Use With Caution
Score 63/100Links shortcode has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "links-shortcode" plugin v1.8.3 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all its SQL queries and has a single capability check for its shortcode, indicating an effort to control access. The attack surface is limited to a single shortcode, and there are no observed file operations or external HTTP requests, reducing potential vectors for attack. However, a significant concern arises from the poor output escaping, with only 9% of outputs being properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious code could be injected and executed within a user's browser.
The vulnerability history is also a major red flag. The plugin has a known CVE, which is currently unpatched and classified as medium severity. The common vulnerability type being XSS further corroborates the concerns raised by the static analysis regarding output escaping. The existence of an unpatched medium-severity vulnerability, coupled with widespread output escaping issues, suggests that the plugin may not be actively maintained with a strong focus on security. While the current version might not have critical or high-severity taint flows identified, the historical pattern and code-level weaknesses point to a substantial risk of exploitation.
In conclusion, despite some good security practices like prepared statements and limited attack surface, the "links-shortcode" plugin v1.8.3 carries a significant risk primarily due to its widespread unescaped output, making it susceptible to XSS attacks. The presence of an unpatched medium-severity vulnerability further amplifies this risk. Users should exercise extreme caution and ideally seek an updated and patched version or an alternative plugin.
Key Concerns
- Unpatched Medium Severity CVE
- Poor output escaping (9% properly escaped)
- No nonce checks
Links shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Links shortcode <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Links shortcode Code Analysis
SQL Query Safety
Output Escaping
Links shortcode Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Links shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Links shortcode Alternatives
No Category Base (WPML)
no-category-base-wpml
This plugin removes the mandatory 'Category Base' from your category permalinks. It's compatible with WPML.
Remove Category URL – Remove 'category' base from category permalinks
remove-category-url
Remove Category URL strips the /category/ base from your category URLs, turning something like /category/my-category/ into simply /my-category/.
No category parents
no-category-parents
This plugin will completely remove the mandatory 'Category Base' and all the parents from your category permalinks (e.g.
Yada Wiki
yada-wiki
Yada Wiki is a simple wiki for your WordPress site.
Blogroll Links
blogroll-links
Display your blogroll links anywhere in posts or pages using a simple shortcode.
Links shortcode Developer Profile
3 plugins · 960 total installs
How We Detect Links shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/links-shortcode/links-shortcode.csslinks-shortcode.css?ver=HTML / DOM Fingerprints
links_sc_fblinks_scitemscopeitemtypeitempropcontent<div itemscope itemtype="http://schema.org/Rating" class="links_sc_fb"><a itemprop="url" href="[link_url]" target="_blank" ><span itemprop="name">[link_name]</span><meta itemprop="worstRating" content="1">