
Magic Links Security & Risk Analysis
wordpress.org/plugins/magic-linksMagic Links is a WordPress plugin that offers a variety of methods to show links.
Is Magic Links Safe to Use in 2026?
Generally Safe
Score 85/100Magic Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The magic-links v1.0.2 plugin exhibits a generally good security posture from a static analysis perspective, with no critical or high severity issues identified in taint analysis and a clean vulnerability history. The absence of dangerous functions, file operations, and external HTTP requests is commendable. However, several areas raise concerns. The plugin uses raw SQL queries without prepared statements, which is a significant risk for SQL injection vulnerabilities. Furthermore, the low percentage of properly escaped output suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, especially considering the presence of a shortcode which represents a potential entry point for user-supplied data that could be rendered unsafely. The complete lack of nonce and capability checks on its entry points also presents a broad attack surface that could be exploited for various malicious actions.
Key Concerns
- Raw SQL queries without prepared statements
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
Magic Links Security Vulnerabilities
Magic Links Release Timeline
Magic Links Code Analysis
SQL Query Safety
Output Escaping
Magic Links Attack Surface
Shortcodes 1
WordPress Hooks 5
Scheduled Events 2
Maintenance & Trust
Magic Links Maintenance & Trust
Maintenance Signals
Community Trust
Magic Links Alternatives
RaraTheme Companion
raratheme-companion
23 extremely useful custom widgets to create an engaging website.
Must Read Posts
must-read-posts
Retrieves posts and pages with a certain custom field (e.g. to permanently show your most recommended posts in a widget) and displays them in a list.
KeenSalon Companion
keensalon-companion
5 extremely useful custom widgets to create an engaging website.
Advanced Random Posts Widget
advanced-random-posts-widget
Provides flexible and advanced random posts. Display it via shortcode or widget with thumbnails, post excerpt, and much more!
Per Page Sidebars
per-page-sidebars
The Per Page Sidebars (PPS) plugin allows blog administrators to create a unique sidebar for each Page. No template editing is required.
Magic Links Developer Profile
1 plugin · 10 total installs
How We Detect Magic Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
magic-linksdata-ml-colordata-ml-font-sizedata-ml-output-styledata-ml-link-separatordata-ml-target-blankdata-ml-nofollow+12 more[MAGIC-LINKS]