
Mention Links Security & Risk Analysis
wordpress.org/plugins/mention-linksThis plugin lets you mention a user or a post (including Custom Post Types) in post content from the block editor. Type @ to link to an author or # to …
Is Mention Links Safe to Use in 2026?
Generally Safe
Score 92/100Mention Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mention-links" v1.0.4 plugin exhibits a very strong security posture based on the provided static analysis. The absence of any identified attack surface entry points, dangerous functions, direct SQL queries, file operations, or external HTTP requests is highly commendable. Furthermore, the 100% proper output escaping and the presence of a capability check indicate robust development practices. The lack of any recorded vulnerabilities or CVEs in its history reinforces this positive assessment, suggesting a well-maintained and secure codebase.
While the static analysis reveals no immediate threats, the complete absence of taint analysis flows is unusual for any plugin with functional code. This could indicate a very limited feature set or, conversely, that the analysis might not have covered all potential code paths. The absence of nonce checks, while not a direct concern given the lack of AJAX/REST API endpoints, would be a significant weakness if such endpoints were ever introduced without proper security measures. Overall, the plugin appears secure, with its strengths lying in its minimal attack surface and adherence to secure coding principles. The primary area to remain vigilant about is the potential for undiscovered vulnerabilities, though the current data suggests this is unlikely.
Mention Links Security Vulnerabilities
Mention Links Code Analysis
Output Escaping
Mention Links Attack Surface
WordPress Hooks 4
Maintenance & Trust
Mention Links Maintenance & Trust
Maintenance Signals
Community Trust
Mention Links Alternatives
Mentions légales [FR]
hjqs-mentions-legales-fr
Le plugin vous permet de générer automatiquement vos mentions légales, votre politique de confidentialité et vos conditions générales de vente en quel …
Display Tweets
display-tweets-php
Display Tweets is an easy to use, future proof Twitter feed plugin that uses PHP to make requests to the v1.1 Twitter REST API.
Mentions Legales Par Webdeclic
mentions-legales-par-webdeclic
Génère un shortcode pour les mentions légales qui sont obligatoires sur les sites internet en France.
BuddyPress Messaging Control
bp-messaging-control
This plugin is a Swiss Army Knife for messaging, It allows the site admin to place restrictions on public and private messages including general rules …
Twitter Mentions As Comments
twitter-mentions-as-comments
Twitter Mentions as Comments scours Twitter for people talking about your site & silently inserts their Tweets alongside your existing comments.
Mention Links Developer Profile
19 plugins · 119K total installs
How We Detect Mention Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mention-links/assets/build/js/main.min.js/wp-content/plugins/mention-links/assets/build/js/main.min.jsHTML / DOM Fingerprints
wpMentionsLinks