
Maja Bookmarks Security & Risk Analysis
wordpress.org/plugins/maja-bookmarksThe Maja Bookmarks plug-in is a widget as well as a shortcode to display a list of bookmarks (links) through several options.
Is Maja Bookmarks Safe to Use in 2026?
Generally Safe
Score 85/100Maja Bookmarks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'maja-bookmarks' plugin v1.1.5.1 exhibits a mixed security posture with some concerning code practices despite a clean vulnerability history. On the positive side, the plugin has no recorded CVEs, indicating a generally stable past. Furthermore, its attack surface is minimal, with only one shortcode and no AJAX handlers, REST API routes, or cron events, which are common vectors for vulnerabilities. All SQL queries are also properly prepared, mitigating the risk of SQL injection.
However, the static analysis reveals significant weaknesses. The use of the deprecated `create_function` is a major concern as it can lead to code injection vulnerabilities if user-supplied data is used within its execution. Critically, a complete lack of output escaping on all identified outputs is a severe oversight, leaving the plugin highly susceptible to Cross-Site Scripting (XSS) attacks. The absence of nonce and capability checks, even with a small attack surface, is also a point of concern, as it implies that actions triggered by the shortcode might not be properly authorized or protected against CSRF.
In conclusion, while the plugin benefits from a clean vulnerability record and a limited attack surface, the identified code signals, particularly the `create_function` usage and the pervasive lack of output escaping, present a substantial risk. These issues could be exploited even without direct CVEs. The absence of security checks like nonces and capability checks further exacerbates these risks.
Key Concerns
- Use of deprecated and dangerous create_function
- 100% of outputs unescaped (XSS risk)
- No nonce checks implemented
- No capability checks implemented
Maja Bookmarks Security Vulnerabilities
Maja Bookmarks Release Timeline
Maja Bookmarks Code Analysis
Dangerous Functions Found
Output Escaping
Maja Bookmarks Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Maja Bookmarks Maintenance & Trust
Maintenance Signals
Community Trust
Maja Bookmarks Alternatives
RaraTheme Companion
raratheme-companion
23 extremely useful custom widgets to create an engaging website.
Disable Author Pages
disable-author-pages
Disable the author pages
Social Media Icon Widget
new-social-media-widget
Add social media icon links to your sidebar with customizable styles, colors, hover effects, and animations.
Sidebar Shortcode
thinker-sidebar-shortcode
Add sidebars to WordPress posts and pages using shortcodes with a sidebar Name or ID.
CC BMI Calculator
cc-bmi-calculator
Add a free simple customizable BMI Calculator to your web site.
Maja Bookmarks Developer Profile
2 plugins · 20 total installs
How We Detect Maja Bookmarks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/maja-bookmarks/css/maja-bookmarks-admin.css/wp-content/plugins/maja-bookmarks/css/maja-bookmarks-front.css/wp-content/plugins/maja-bookmarks/js/maja-bookmarks-admin.js/wp-content/plugins/maja-bookmarks/js/maja-bookmarks-front.js/wp-content/plugins/maja-bookmarks/js/maja-bookmarks-admin.js/wp-content/plugins/maja-bookmarks/js/maja-bookmarks-front.jsmaja-bookmarks/css/maja-bookmarks-admin.css?ver=maja-bookmarks/css/maja-bookmarks-front.css?ver=maja-bookmarks/js/maja-bookmarks-admin.js?ver=maja-bookmarks/js/maja-bookmarks-front.js?ver=HTML / DOM Fingerprints
maja-bookmarks-front-widget<div class="maja-bookmarks-front-widget">