
PostLinks Security & Risk Analysis
wordpress.org/plugins/postlinks(Beta) An extension of Fields, a custom field management plugin. PostLinks provides additional field types such as Series, PhotoLink and PostLink.
Is PostLinks Safe to Use in 2026?
Generally Safe
Score 85/100PostLinks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "postlinks" plugin v0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no recorded vulnerability history, suggesting a generally secure development approach so far. However, significant concerns arise from the static analysis. The plugin has a notable attack surface, with 2 out of 3 entry points being unprotected AJAX handlers. Furthermore, a very low percentage (4%) of outputs are properly escaped, creating a high risk of cross-site scripting (XSS) vulnerabilities. The complete absence of nonce checks on any of the entry points exacerbates the risk associated with unprotected AJAX handlers. While no critical taint flows or dangerous functions were detected in this analysis, the identified weaknesses, particularly the unprotected AJAX endpoints and poor output escaping, present a substantial risk. The lack of vulnerability history is positive but does not negate the current security flaws.
Key Concerns
- 2 unprotected AJAX handlers
- 4% properly escaped outputs
- 0 Nonce checks found
PostLinks Security Vulnerabilities
PostLinks Code Analysis
SQL Query Safety
Output Escaping
PostLinks Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
PostLinks Maintenance & Trust
Maintenance Signals
Community Trust
PostLinks Alternatives
Custom Fields Permalink 2
custom-fields-permalink-redux
Plugin allows to use post's custom fields values in permalink structure by adding %field_fieldname%, for posts, pages and custom post types.
Show Hidden Post Meta
show-hidden-post-meta
Makes hidden post meta visible on post edit screens
WP-Admin Search Post Meta
wp-admin-search-meta
Enables searching post meta fields on admin pages.
List More Custom Field Names
list-more-custom-field-names
Allows for more existing custom field names to be listed in the dropdown selection field when writing a post.
Enable posts order
enable-posts-order
Order posts using a simple drag and drop ui.
PostLinks Developer Profile
2 plugins · 510 total installs
How We Detect PostLinks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/postlinks/css/links.css/wp-content/plugins/postlinks/js/links.js/wp-content/plugins/postlinks/js/links.jspostlinks/js/links.js?ver=1.0HTML / DOM Fingerprints
fs-series-linked<ul class="ls-series"><a href={$post->part}$ - {$post->post_title}{$post->post_title}