
Preview Link Generator Security & Risk Analysis
wordpress.org/plugins/preview-link-generatorPreview Link Generator is a plugin to help you create demo/preview links for your WordPress themes, plugins, HTML templates preview.
Is Preview Link Generator Safe to Use in 2026?
Generally Safe
Score 92/100Preview Link Generator has a strong security track record. Known vulnerabilities have been patched promptly.
The "preview-link-generator" plugin v1.0.6 demonstrates a generally strong security posture based on the provided static analysis. The absence of identified vulnerabilities in taint analysis and a lack of dangerous function usage are positive indicators. The code also shows good practices in SQL query handling (100% prepared statements) and a reasonable percentage of properly escaped output (77%). The presence of nonce and capability checks further contributes to its secure design.
However, the plugin has a history of one known CVE, a medium severity Cross-Site Request Forgery (CSRF) vulnerability, which was patched. While there are currently no unpatched vulnerabilities, this history suggests a past weakness that required remediation. The static analysis reports zero attack surface points, which is excellent, but it's important to note that static analysis tools may not always identify every potential entry point, especially for less conventional attack vectors. The limited scope of taint analysis (0 flows analyzed) means that the absence of critical or high severity flows cannot be definitively declared a permanent state of security.
Overall, the plugin appears to be developed with security in mind, adhering to several best practices. The past CVE, though patched, serves as a reminder to remain vigilant. The low attack surface and good internal code practices are strengths. The key weakness is the past vulnerability history, indicating that while currently secure, ongoing monitoring and updates are crucial for maintaining this state.
Key Concerns
- Past medium severity CVE
Preview Link Generator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Preview Link Generator <= 1.0.3 - Cross-Site Request Forgery to Arbitrary Plugin Activation
Preview Link Generator Code Analysis
Output Escaping
Preview Link Generator Attack Surface
WordPress Hooks 11
Maintenance & Trust
Preview Link Generator Maintenance & Trust
Maintenance Signals
Community Trust
Preview Link Generator Alternatives
Meks ThemeForest Smart Widget
meks-themeforest-smart-widget
Easily display ThemeForest items inside WordPress widget.
GS Portfolio for Envato
gs-envato-portfolio
Best Responsive Envato Portfolio Plugin to display Themeforest & Codecanyon Items.
Backstage – Customizer Demo Access
backstage
Showcase your product's flexibility the same way users will harness it, in the Customizer. All elegant and secure.
My Envato
my-envato
A super simple plugin to display your recent 25 items from an Envato Marketplace.
Demonstrator
demonstrator
More than a theme switcher!
Preview Link Generator Developer Profile
14 plugins · 16K total installs
How We Detect Preview Link Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/preview-link-generator/assets/css/style.css/wp-content/plugins/preview-link-generator/assets/js/main.js/wp-content/plugins/preview-link-generator/libs/codestar-framework/assets/js/codestar-framework.js/wp-content/plugins/preview-link-generator/libs/codestar-framework/assets/js/beta-beta.js/wp-content/plugins/preview-link-generator/libs/codestar-framework/assets/js/import-export.js/wp-content/plugins/preview-link-generator/assets/js/main.jspreview-link-generator/assets/css/style.css?ver=preview-link-generator/assets/js/main.js?ver=codestar-framework.js?ver=beta-beta.js?ver=import-export.js?ver=HTML / DOM Fingerprints
htpl-admin-wrapdata-field-iddata-dependencydata-outputdata-validatedata-titledata-modal-id+6 morehtpl_generator_params