MtG-Tutor.de CardLinker Security & Risk Analysis

wordpress.org/plugins/mtg-tutorde-cardlinker

This plugin provides some shortcode to easily link MtG Cards and Decks! - Ein Plugin mit dem man ganz leicht MtG Karten und Decks verlinken kann!

10 active installs v0.1 PHP + WP 3.0.1+ Updated Oct 7, 2012
magic-the-gatheringmtgtcgtrading-cards
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MtG-Tutor.de CardLinker Safe to Use in 2026?

Generally Safe

Score 85/100

MtG-Tutor.de CardLinker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The mtg-tutorde-cardlinker v0.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, file operations, and external HTTP requests. All SQL queries are prepared, and capability checks are in place for its entry points. The lack of known vulnerabilities in its history is also a positive indicator.

However, there are significant concerns. The plugin has a very low percentage (23%) of properly escaped output, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the static analysis reported no critical taint flows, the lack of thorough taint analysis (0 flows analyzed) means that potential vulnerabilities could be missed. Furthermore, the absence of nonce checks on its entry points, combined with a notable portion of unescaped output, is a substantial security weakness that could be exploited.

In conclusion, while the plugin has a clean vulnerability history and avoids some common pitfalls, the severe lack of output escaping and the absence of nonce checks present critical risks. These issues indicate a need for significant improvement in secure coding practices, particularly concerning input validation and output sanitization, to mitigate potential XSS attacks.

Key Concerns

  • Low output escaping percentage
  • No nonce checks on entry points
  • Limited taint analysis coverage
Vulnerabilities
None known

MtG-Tutor.de CardLinker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

MtG-Tutor.de CardLinker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
3 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

23% escaped13 total outputs
Attack Surface

MtG-Tutor.de CardLinker Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[mt_card] mtutor_cardlinker.php:111
[mt_deck] mtutor_cardlinker.php:112
WordPress Hooks 7
actionadmin_initincludes\mtutor_options_page.php:265
actionwp_footermtutor_cardlinker.php:122
filtermce_external_pluginsmtutor_cardlinker.php:137
filtermce_buttonsmtutor_cardlinker.php:138
actioninitmtutor_cardlinker.php:177
actionadmin_menumtutor_cardlinker.php:187
filtertiny_mce_versionmtutor_cardlinker.php:199
Maintenance & Trust

MtG-Tutor.de CardLinker Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedOct 7, 2012
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

MtG-Tutor.de CardLinker Developer Profile

pascalkleindienst

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MtG-Tutor.de CardLinker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mtg-tutorde-cardlinker/css/mt_deck.css
Script Paths
/wp-content/plugins/mtg-tutorde-cardlinker/js/mt_card_hover.js/wp-content/plugins/mtg-tutorde-cardlinker/js/mt_card_editor_plugin.js/wp-content/plugins/mtg-tutorde-cardlinker/js/mt_deck_editor_plugin.js
Version Parameters
mtg-tutorde-cardlinker/css/mt_deck.css?ver=mtg-tutorde-cardlinker/js/mt_card_hover.js?ver=mtg-tutorde-cardlinker/js/mt_card_editor_plugin.js?ver=mtg-tutorde-cardlinker/js/mt_deck_editor_plugin.js?ver=

HTML / DOM Fingerprints

JS Globals
mt_cardlinkermt_decklinker
FAQ

Frequently Asked Questions about MtG-Tutor.de CardLinker