
CDN Linker lite Security & Risk Analysis
wordpress.org/plugins/ossdl-cdn-off-linkerRewrites links to static files to your own CDN network.
Is CDN Linker lite Safe to Use in 2026?
Use With Caution
Score 63/100CDN Linker lite has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "ossdl-cdn-off-linker" plugin version 1.3.1 exhibits a generally good security posture in terms of its exposed attack surface and its handling of database operations. There are no detected AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited. Furthermore, all SQL queries are properly prepared, which significantly mitigates the risk of SQL injection vulnerabilities. The lack of any recorded vulnerabilities in its history is also a positive indicator of past security diligence.
However, there are significant concerns raised by the static analysis. Notably, 100% of the detected output operations are not properly escaped. This presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the user's browser. The taint analysis revealing two flows with unsanitized paths further reinforces this concern, suggesting that data entering the plugin may not be sufficiently validated or cleaned before being outputted. While the attack surface is minimal, the lack of capability checks and nonce checks on any potential, albeit currently non-existent, entry points means that if new entry points were added in the future without proper security measures, they could be immediately vulnerable.
In conclusion, while the plugin's core structure appears robust against common web application attacks like SQL injection and has a clean vulnerability history, the complete lack of output escaping is a critical weakness. This, combined with the taint analysis findings, makes XSS a significant threat. The absence of capability and nonce checks, while not an immediate problem due to the zero attack surface, represents a missed opportunity for defensive coding practices.
Key Concerns
- Unescaped output detected
- Taint flows with unsanitized paths
- No capability checks
- No nonce checks
CDN Linker lite Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CDN Linker lite <= 1.3.1 - Cross-Site Request Forgery to Plugin Settings Update
CDN Linker lite Release Timeline
CDN Linker lite Code Analysis
Output Escaping
Data Flow Analysis
CDN Linker lite Attack Surface
WordPress Hooks 2
Maintenance & Trust
CDN Linker lite Maintenance & Trust
Maintenance Signals
Community Trust
CDN Linker lite Alternatives
Social Media Icon Widget – Social Profile Links with Gutenberg Block
new-social-media-widget
Add a social media icon list. Display social icons and social profile links using a widget or a Gutenberg block.
WP Social Widget
wp-social-widget
A widget to add links of social networking sites.
C3 Cloudfront Cache Controller
c3-cloudfront-clear-cache
This is simple plugin that clear all cloudfront cache if you publish posts.
Microsoft Azure Storage for WordPress
windows-azure-storage
Use the Microsoft Azure Storage service to host your website's media files.
Offload Media – Cloud Storage
offload-media-cloud-storage
Offload Media moves your WordPress files to cloud storage (AWS S3, DigitalOcean, Cloudflare R2, Google Cloud) to improve site performance.
CDN Linker lite Developer Profile
1 plugin · 20 total installs
How We Detect CDN Linker lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ossdl-cdn-off-linker//wp-includes/HTML / DOM Fingerprints
name="ossdl_off_cdn_url"name="ossdl_off_include_dirs"name="ossdl_off_exclude"name="ossdl_off_rootrelative"value="update_ossdl_off"