
Linkz.ai – Automatic link previews on hover Security & Risk Analysis
wordpress.org/plugins/linkz-aiLinkz.ai improves visitor retention on your website & blog with live link previews. Linkz.ai automatically extracts & shows linked content, e.
Is Linkz.ai – Automatic link previews on hover Safe to Use in 2026?
Generally Safe
Score 91/100Linkz.ai – Automatic link previews on hover has a strong security track record. Known vulnerabilities have been patched promptly.
The "linkz-ai" v1.3.0 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a small attack surface with no unprotected entry points and a complete reliance on prepared statements for SQL queries. The plugin also demonstrates good practices with a healthy number of nonce and capability checks. Taint analysis shows no critical or high-severity unsanitized flows.
However, concerns arise from the output escaping, where only 57% of outputs are properly escaped, leaving potential for cross-site scripting (XSS) vulnerabilities. While there are no currently unpatched CVEs, the plugin has a history of two medium-severity vulnerabilities, both stemming from missing authorization issues. This historical pattern suggests a recurring oversight in securing sensitive operations, even though the current analysis shows no immediate auth bypasses in the entry points.
Overall, the plugin has made strides in secure coding practices, particularly with SQL handling and a protected attack surface. The primary remaining risk is the inconsistent output escaping and the historical precedent of authorization flaws. While no critical issues are immediately apparent in this version's static analysis, the past vulnerability types warrant continued vigilance regarding authorization and the identified output escaping weaknesses.
Key Concerns
- Inconsistent output escaping
- History of missing authorization vulns
Linkz.ai – Automatic link previews on hover Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Linkz.ai <= 1.1.8 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update via AJAX
Linkz.ai <= 1.1.8 - Missing Authorization to Unauthenticated Plugin Settings Update
Linkz.ai – Automatic link previews on hover Code Analysis
Output Escaping
Data Flow Analysis
Linkz.ai – Automatic link previews on hover Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Linkz.ai – Automatic link previews on hover Maintenance & Trust
Maintenance Signals
Community Trust
Linkz.ai – Automatic link previews on hover Alternatives
GW Elementor Addons
gw-elementor-addons
GW Elementor Addons – Take your Elementor designs to the next level with 40+ premium widgets, 120+ templates, and many more.
Free widgets For Elementor
free-widgets-for-elementor
Free widgets For Elementor is a collection of powerful widgets that works perfectly with Elementor page builder. It has many widgets so you can easy-t …
Just show free stuff in Elementor
just-show-free-stuff-in-elementor
This plug-in will remove/hide pro features so the interface will be a bit cleaner.
AddonNest for Elementor
addonnest
Supercharge Elementor with 20+ premium-quality widgets for stunning websites. No coding needed!
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Linkz.ai – Automatic link previews on hover Developer Profile
1 plugin · 80 total installs
How We Detect Linkz.ai – Automatic link previews on hover
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/linkz-ai/assets/img/icon-16x16.png/wp-content/plugins/linkz-ai/assets/js/admin.jslinkz-ai/assets/js/admin.js?ver=linkz-ai/assets/css/admin.css?ver=HTML / DOM Fingerprints
linkzAi