MM LinkedIn Connection Security & Risk Analysis

wordpress.org/plugins/mm-linkedin-connect

This Plugin Allow you to have LinkedIn Social Login in your site.

10 active installs v1 PHP + WP 3.0.1+ Updated Nov 19, 2015
linkedinlinkedin-connectlinkedin-signupsignupsocial-login
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MM LinkedIn Connection Safe to Use in 2026?

Generally Safe

Score 85/100

MM LinkedIn Connection has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "mm-linkedin-connect" v1 plugin exhibits a mixed security posture. On the positive side, it has no known CVEs and no dangerous functions are present in the code. All SQL queries utilize prepared statements, and there are no file operations, which are good indicators of secure coding practices. The absence of bundled libraries and a limited number of external HTTP requests also contribute to a reduced attack surface. However, significant concerns arise from the output escaping. With 13 outputs and 0% properly escaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities if any user-controlled data finds its way into these outputs. Additionally, the single taint flow with an unsanitized path, even if not flagged as critical or high severity in this analysis, represents a potential entry point for malicious input to be processed insecurely. The presence of only one capability check and zero nonce checks on entry points (though the attack surface is reported as zero) suggests a lack of robust authorization and session validation for any potential interactions.

Key Concerns

  • Output escaping is completely missing
  • Taint flow with unsanitized path detected
  • Limited capability checks
  • No nonce checks on entry points
Vulnerabilities
None known

MM LinkedIn Connection Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MM LinkedIn Connection Release Timeline

v1.0
Code Analysis
Analyzed Mar 17, 2026

MM LinkedIn Connection Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

0% escaped13 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
mm_linkedin_connection_process_linkedin_actions (mm-linkedin-connect.php:13)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MM LinkedIn Connection Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitmm-linkedin-connect.php:12
actionadmin_initmm-linkedin-connect.php:59
actionadmin_headmm-linkedin-connect.php:179
actionlogin_headmm-linkedin-connect.php:180
actionwp_headmm-linkedin-connect.php:181
actionprofile_personal_optionsmm-linkedin-connect.php:227
actionlogin_formmm-linkedin-connect.php:256
Maintenance & Trust

MM LinkedIn Connection Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedNov 19, 2015
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

MM LinkedIn Connection Developer Profile

Rodrigo Techera

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MM LinkedIn Connection

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
mm-sl-btnmm-sl-fbmm-sl-twmm-sl-gomm-sl-limm-sl-inmm-sl-pimm-sl-gi
Data Attributes
id="mm_connection_settings"id="mm_linkedin_connection_settings"
FAQ

Frequently Asked Questions about MM LinkedIn Connection