Mention Links Security & Risk Analysis

wordpress.org/plugins/mention-links

This plugin lets you mention a user or a post (including Custom Post Types) in post content from the block editor. Type @ to link to an author or # to …

20 active installs v1.0.4 PHP 7.0+ WP 5.0+ Updated Jul 22, 2024
cpt-mentionscustom-post-types-mentionsmentionspost-mentionsuser-mentions
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mention Links Safe to Use in 2026?

Generally Safe

Score 92/100

Mention Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "mention-links" v1.0.4 plugin exhibits a very strong security posture based on the provided static analysis. The absence of any identified attack surface entry points, dangerous functions, direct SQL queries, file operations, or external HTTP requests is highly commendable. Furthermore, the 100% proper output escaping and the presence of a capability check indicate robust development practices. The lack of any recorded vulnerabilities or CVEs in its history reinforces this positive assessment, suggesting a well-maintained and secure codebase.

While the static analysis reveals no immediate threats, the complete absence of taint analysis flows is unusual for any plugin with functional code. This could indicate a very limited feature set or, conversely, that the analysis might not have covered all potential code paths. The absence of nonce checks, while not a direct concern given the lack of AJAX/REST API endpoints, would be a significant weakness if such endpoints were ever introduced without proper security measures. Overall, the plugin appears secure, with its strengths lying in its minimal attack surface and adherence to secure coding principles. The primary area to remain vigilant about is the potential for undiscovered vulnerabilities, though the current data suggests this is unlikely.

Vulnerabilities
None known

Mention Links Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Mention Links Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
19 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped19 total outputs
Attack Surface

Mention Links Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionenqueue_block_editor_assetsinc\classes\class-assets.php:36
actionadmin_initinc\classes\plugin-configs\class-plugin-settings.php:35
actionadmin_menuinc\classes\plugin-configs\class-plugin-settings.php:36
actionadmin_noticesinc\classes\plugin-configs\class-plugin-settings.php:37
Maintenance & Trust

Mention Links Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 22, 2024
PHP min version7.0
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Mention Links Developer Profile

rtCamp

19 plugins · 119K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
883 days
View full developer profile
Detection Fingerprints

How We Detect Mention Links

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mention-links/assets/build/js/main.min.js
Script Paths
/wp-content/plugins/mention-links/assets/build/js/main.min.js

HTML / DOM Fingerprints

JS Globals
wpMentionsLinks
FAQ

Frequently Asked Questions about Mention Links