
NG Secret link Security & Risk Analysis
wordpress.org/plugins/ng-secret-linkMake your site accessible only with secret link
Is NG Secret link Safe to Use in 2026?
Generally Safe
Score 85/100NG Secret link has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ng-secret-link v1.0 plugin exhibits a seemingly strong security posture based on the provided static analysis. The absence of any identified attack surface points like AJAX handlers, REST API routes, shortcodes, or cron events is a significant positive. Furthermore, the code analysis shows no dangerous functions, file operations, or external HTTP requests, and all SQL queries utilize prepared statements. This indicates a good understanding of secure coding practices regarding common WordPress vulnerabilities. The lack of any recorded vulnerabilities in its history also suggests a history of stable and secure development.
However, a critical concern arises from the output escaping metrics. With 19 total outputs and only 5% properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This is the most prominent weakness identified in the static analysis. The absence of nonce checks and capability checks, while not directly tied to an attack surface in this specific analysis, could become a vulnerability if the attack surface were to expand in future versions or if certain functionalities were introduced without proper authorization checks.
In conclusion, ng-secret-link v1.0 has a low attack surface and uses prepared statements for SQL, which are excellent security strengths. Its vulnerability history is clean. The primary and significant risk is the widespread lack of proper output escaping, leaving it vulnerable to XSS attacks. The absence of nonce and capability checks on the current, albeit small, attack surface are potential future risks. Addressing the output escaping is paramount to improving its security.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks found
- No capability checks found
NG Secret link Security Vulnerabilities
NG Secret link Release Timeline
NG Secret link Code Analysis
Output Escaping
NG Secret link Attack Surface
WordPress Hooks 5
Maintenance & Trust
NG Secret link Maintenance & Trust
Maintenance Signals
Community Trust
NG Secret link Alternatives
My Private Site
jonradio-private-site
Make your WordPress site private with one click for family, projects, or teams. Protection for content, login, and registration.
The GDPR Framework By Data443
gdpr-framework
Easy to use tools to help make your website GDPR-compliant. Fully documented, extendable and developer-friendly. Extensions to enterprise GDPR compli …
Restricted Site Access
restricted-site-access
Limit access to visitors who are logged in or allowed by IP addresses. Includes many options for handling blocked visitors.
Logout Clear Cookies
logout-clear-cookies
Clears all domain cookies on logout. Because leaving a trail of cookies is bad.
WP Author Security
wp-author-security
Protect against user enumeration attacks on author pages and other places where valid user names can be obtained.
NG Secret link Developer Profile
4 plugins · 20 total installs
How We Detect NG Secret link
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ng-secret-link/js/ng-secret-link.js/wp-content/plugins/ng-secret-link/css/ng-secret-link.css/wp-content/plugins/ng-secret-link/js/ng-secret-link.jsng-secret-link/js/ng-secret-link.js?ver=ng-secret-link/css/ng-secret-link.css?ver=HTML / DOM Fingerprints
data-val=""id="ng-secret-linkcopy"id="nghidden"ngcopytext()