
OrphanPages – Internal Link Audit, Orphaned Pages, Broken Links & SEO Content Structure Analyzer Security & Risk Analysis
wordpress.org/plugins/orphanpagesA complete internal linking and link health audit tool for WordPress. Identify orphaned pages, analyze incoming and outgoing links, detect broken link …
Is OrphanPages – Internal Link Audit, Orphaned Pages, Broken Links & SEO Content Structure Analyzer Safe to Use in 2026?
Generally Safe
Score 100/100OrphanPages – Internal Link Audit, Orphaned Pages, Broken Links & SEO Content Structure Analyzer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "orphanpages" plugin v4.0.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The plugin has no identified CVEs, a testament to its secure development or lack of past exploitable issues. The static analysis reveals a minimal attack surface with zero unprotected entry points across AJAX handlers, REST API routes, shortcodes, and cron events. This suggests robust authentication and authorization mechanisms are in place for any potential interaction points.
However, a significant concern arises from the output escaping. With 32 total outputs and only 31% properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. While the taint analysis found no unsanitized paths, the high percentage of unescaped output creates a potential avenue for attackers to inject malicious scripts if data originating from user input or external sources is not adequately sanitized before display. The presence of only one nonce check and one capability check, while indicating some security measures, could be insufficient for a plugin with a larger or more complex feature set.
Overall, the plugin's lack of known vulnerabilities and protected attack surface are positive indicators. The primary weakness lies in the insufficient output escaping, which requires immediate attention. The history of zero vulnerabilities is a strong positive, but it should not overshadow the critical XSS risk identified in the code signals.
Key Concerns
- Low percentage of properly escaped output
OrphanPages – Internal Link Audit, Orphaned Pages, Broken Links & SEO Content Structure Analyzer Security Vulnerabilities
OrphanPages – Internal Link Audit, Orphaned Pages, Broken Links & SEO Content Structure Analyzer Code Analysis
SQL Query Safety
Output Escaping
OrphanPages – Internal Link Audit, Orphaned Pages, Broken Links & SEO Content Structure Analyzer Attack Surface
WordPress Hooks 2
Maintenance & Trust
OrphanPages – Internal Link Audit, Orphaned Pages, Broken Links & SEO Content Structure Analyzer Maintenance & Trust
Maintenance Signals
Community Trust
OrphanPages – Internal Link Audit, Orphaned Pages, Broken Links & SEO Content Structure Analyzer Alternatives
Linkable
linkable
Automatically link keywords in your content to internal pages or posts. Simple, fast, and Gutenberg-compatible.
HGW Better internal link search for Block editor
hgw-better-internal-link-search-for-block-editor
Improved internal link search in the block editor linkControl popup by adding an option to search by post type and taxonomy.
AI Internal Linking Manager
kumarharshit-ai-internal-linking-tool
Advanced automatic internal linking - Smart keyword detection and performance optimization.
Ozi Internal Link Booster — Smart Internal Linking for SEO
ozi-internal-link-booster
Smart, SEO-safe internal linking with keyword mapping, orphan page detection, and lightweight automation. No bloat. No risk.
Internal Link Juicer: SEO Auto Linker for WordPress
internal-links
Improve your SEO and your user experience through internal linkbuilding. Automated links between your posts based on a smart keyword configuration.
OrphanPages – Internal Link Audit, Orphaned Pages, Broken Links & SEO Content Structure Analyzer Developer Profile
3 plugins · 110 total installs
How We Detect OrphanPages – Internal Link Audit, Orphaned Pages, Broken Links & SEO Content Structure Analyzer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/orphanpages/dist/css/orphanpages-admin.css/wp-content/plugins/orphanpages/dist/js/orphanpages-admin.js/wp-content/plugins/orphanpages/dist/js/orphanpages-admin.jsorphanpages/dist/css/orphanpages-admin.css?ver=orphanpages/dist/js/orphanpages-admin.js?ver=HTML / DOM Fingerprints
orphanpages-settings-pageorphanpages-status-icon-orphanorphanpages-status-icon-internalorphanpages-status-icon-externalorphanpages-link-status-orphanorphanpages-link-status-internalorphanpages-link-status-externalorphanpages-button-scan<!-- orphanpages output -->data-orphanpages-scan-nonceorphanpagesScanNonce/wp-json/orphanpages/v1/scan