
Local Links Security & Risk Analysis
wordpress.org/plugins/local-linksAlter vendor links so that they go to the user's local store, and optionally add affiliate codes. Some functions require the GeoIP Detection plugin.
Is Local Links Safe to Use in 2026?
Generally Safe
Score 100/100Local Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "local-links" v4.10 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identifiable attack surface entry points, dangerous functions, raw SQL queries, or external HTTP requests is highly commendable. Furthermore, the near-perfect output escaping (94%) and the presence of nonce and capability checks indicate good development practices aimed at preventing common vulnerabilities. The taint analysis also reveals no critical or high severity flows with unsanitized paths, suggesting that data handling is robust.
The plugin's vulnerability history is exceptionally clean, with zero recorded CVEs across all severity levels. This lack of past issues, combined with the current static analysis findings, strongly suggests a well-maintained and secure codebase. However, even with these positive indicators, it is important to remember that no software is entirely immune to future vulnerabilities. The current analysis, while thorough, is a snapshot in time, and ongoing monitoring and updates are always recommended for any WordPress plugin.
In conclusion, "local-links" v4.10 appears to be a highly secure plugin. The developers have implemented sound security practices throughout the code, and the absence of any historical vulnerabilities further reinforces this assessment. While the attack surface is effectively zero and data sanitization is strong, continuous vigilance and prompt patching of any future disclosed issues would maintain this excellent security reputation.
Local Links Security Vulnerabilities
Local Links Code Analysis
Output Escaping
Data Flow Analysis
Local Links Attack Surface
WordPress Hooks 3
Maintenance & Trust
Local Links Maintenance & Trust
Maintenance Signals
Community Trust
Local Links Alternatives
SmartLink Dynamic URLs
smartlink-dinamic-urls
Attach up to 5 URLs to a single link in random way or depending on user geo-localization.
No Category Base (WPML)
no-category-base-wpml
This plugin removes the mandatory 'Category Base' from your category permalinks. It's compatible with WPML.
Export All URLs
export-all-urls
This plugin enables you to extract information such as Title, URL, Categories, Tags, Author, as well as Published and Modified dates for built-in post …
Remove Category URL – Remove 'category' base from category permalinks
remove-category-url
Remove Category URL strips the /category/ base from your category URLs, turning something like /category/my-category/ into simply /my-category/.
Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links
update-urls
Quick and Easy way to search all URLS, Content and replace them with new links and content in WordPress website.
Local Links Developer Profile
4 plugins · 490 total installs
How We Detect Local Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/local-links/public/replace.js/wp-content/plugins/local-links/public/replace.css/wp-content/plugins/local-links/public/replace.jslocal-links/public/replace.js?ver=local-links/public/replace.css?ver=HTML / DOM Fingerprints
<!-- Local Links plugin by Author Help -->data-locallinks-amazondata-locallinks-appledata-locallinks-kobodata-locallinks-alibrisdata-locallinks-googledata-locallinks-abe+2 morewindow.locallinks_opts