
SMu Manual DoFollow Security & Risk Analysis
wordpress.org/plugins/manuall-dofollowSMu DoFollow has many DoFollow Options (Manual or Automatism) and included URL Validator (Manual, WP-Cron or Cronjob).
Is SMu Manual DoFollow Safe to Use in 2026?
Use With Caution
Score 63/100SMu Manual DoFollow has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "manuall-dofollow" v1.8.1 plugin presents a mixed security posture. While it boasts a zero attack surface from common entry points like AJAX, REST API, and shortcodes, indicating a potentially minimal direct exposure, significant concerns arise from its code analysis and vulnerability history. The complete lack of output escaping across all identified outputs is a critical flaw, exposing users to Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history of such issues.
The taint analysis reveals three high-severity flows with unsanitized paths, directly pointing to potential injection vulnerabilities. Coupled with a notable percentage of SQL queries not using prepared statements, this suggests a susceptibility to SQL injection risks. The plugin also exhibits a concerning absence of nonce and capability checks, meaning that any functionality, if discovered, could be exploited without proper authorization.
Furthermore, the plugin has a history of at least one known CVE, which is currently unpatched and was a medium-severity XSS vulnerability. This pattern of XSS vulnerabilities, combined with the lack of escaping in the current version, indicates a recurring and unaddressed security weakness. The presence of file operations and external HTTP requests, while not inherently insecure, adds to the overall complexity and potential for unintended consequences when combined with other identified weaknesses.
In conclusion, while the plugin has a limited direct attack surface, the severe lack of output escaping, high-severity taint flows, potential for SQL injection, and history of unpatched XSS vulnerabilities paint a worrying picture. The absence of critical security measures like nonce and capability checks further exacerbates these risks. Users should exercise extreme caution, and the developers should prioritize addressing the fundamental security flaws in output handling and input validation.
Key Concerns
- Unpatched CVE history
- High severity taint flows (3)
- No output escaping
- SQL queries without prepared statements (84%)
- No nonce checks
- No capability checks
SMu Manual DoFollow Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
SMu Manual DoFollow <= 1.8.1 - Reflected Cross-Site Scripting
SMu Manual DoFollow Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SMu Manual DoFollow Attack Surface
WordPress Hooks 7
Maintenance & Trust
SMu Manual DoFollow Maintenance & Trust
Maintenance Signals
Community Trust
SMu Manual DoFollow Alternatives
DoFollow Case by Case
dofollow-case-by-case
DoFollow Case by Case allows you to selectively apply dofollow to comments and make links in pages or posts nofollow.
Hide Trackbacks
hide-trackbacks
Prevents trackbacks and pingbacks from showing up as comments on posts.
Nofollow Case by Case
nofollow-case-by-case
"Dofollow" but Nofollow Case by Case allows you to selectively apply nofollow to your comments as well.
Really Simple Disable Comments
really-simple-disable-comments
Effortlessly disable all comments and trackback functionality across your entire WordPress site by activating this plugin.
Pingback Killer
pingback-killer
Pingback Killer disables all of WordPress' pingback functionality.
SMu Manual DoFollow Developer Profile
2 plugins · 110 total installs
How We Detect SMu Manual DoFollow
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/manuall-dofollow/css/style.css/wp-content/plugins/manuall-dofollow/js/smudofollow.js/wp-content/plugins/manuall-dofollow/js/smudofollow.jsmanuall-dofollow/css/style.css?ver=manuall-dofollow/js/smudofollow.js?ver=HTML / DOM Fingerprints
misc-pub-sectionjQuery