Preview Link Generator Security & Risk Analysis

wordpress.org/plugins/preview-link-generator

Preview Link Generator is a plugin to help you create demo/preview links for your WordPress themes, plugins, HTML templates preview.

100 active installs v1.0.6 PHP 7.4+ WP 5.0+ Updated Nov 11, 2024
demoenvatolink-generatorpreviewthemeforest
92
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 28, 2023
Safety Verdict

Is Preview Link Generator Safe to Use in 2026?

Generally Safe

Score 92/100

Preview Link Generator has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 28, 2023Updated 1yr ago
Risk Assessment

The "preview-link-generator" plugin v1.0.6 demonstrates a generally strong security posture based on the provided static analysis. The absence of identified vulnerabilities in taint analysis and a lack of dangerous function usage are positive indicators. The code also shows good practices in SQL query handling (100% prepared statements) and a reasonable percentage of properly escaped output (77%). The presence of nonce and capability checks further contributes to its secure design.

However, the plugin has a history of one known CVE, a medium severity Cross-Site Request Forgery (CSRF) vulnerability, which was patched. While there are currently no unpatched vulnerabilities, this history suggests a past weakness that required remediation. The static analysis reports zero attack surface points, which is excellent, but it's important to note that static analysis tools may not always identify every potential entry point, especially for less conventional attack vectors. The limited scope of taint analysis (0 flows analyzed) means that the absence of critical or high severity flows cannot be definitively declared a permanent state of security.

Overall, the plugin appears to be developed with security in mind, adhering to several best practices. The past CVE, though patched, serves as a reminder to remain vigilant. The low attack surface and good internal code practices are strengths. The key weakness is the past vulnerability history, indicating that while currently secure, ongoing monitoring and updates are crucial for maintaining this state.

Key Concerns

  • Past medium severity CVE
Vulnerabilities
1

Preview Link Generator Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-1086medium · 4.3Cross-Site Request Forgery (CSRF)

Preview Link Generator <= 1.0.3 - Cross-Site Request Forgery to Arbitrary Plugin Activation

Feb 28, 2023 Patched in 1.0.4 (329d)
Code Analysis
Analyzed Mar 16, 2026

Preview Link Generator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
47 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

77% escaped61 total outputs
Attack Surface

Preview Link Generator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_menuincludes\Admin\Recommended_Plugins.php:78
actionadmin_enqueue_scriptsincludes\Admin\Recommended_Plugins.php:79
actionadmin_enqueue_scriptsincludes\Admin.php:16
filterplugin_action_links_preview-link-generator/preview_link_generator.phpincludes\Admin.php:19
actioninitincludes\Custom_Posts.php:15
filterpost_type_linkincludes\Custom_Posts.php:22
filterrequestincludes\Custom_Posts.php:25
filtersingle_templateincludes\Frontend.php:12
actioninitincludes\Taxonomies.php:13
actionplugins_loadedpreview_link_generator.php:123
actionplugins_loadedpreview_link_generator.php:126
Maintenance & Trust

Preview Link Generator Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 11, 2024
PHP min version7.4
Downloads7K

Community Trust

Rating90/100
Number of ratings2
Active installs100
Developer Profile

Preview Link Generator Developer Profile

HasThemes

14 plugins · 16K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
179 days
View full developer profile
Detection Fingerprints

How We Detect Preview Link Generator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/preview-link-generator/assets/css/style.css/wp-content/plugins/preview-link-generator/assets/js/main.js
Script Paths
/wp-content/plugins/preview-link-generator/libs/codestar-framework/assets/js/codestar-framework.js/wp-content/plugins/preview-link-generator/libs/codestar-framework/assets/js/beta-beta.js/wp-content/plugins/preview-link-generator/libs/codestar-framework/assets/js/import-export.js/wp-content/plugins/preview-link-generator/assets/js/main.js
Version Parameters
preview-link-generator/assets/css/style.css?ver=preview-link-generator/assets/js/main.js?ver=codestar-framework.js?ver=beta-beta.js?ver=import-export.js?ver=

HTML / DOM Fingerprints

CSS Classes
htpl-admin-wrap
Data Attributes
data-field-iddata-dependencydata-outputdata-validatedata-titledata-modal-id+6 more
JS Globals
htpl_generator_params
FAQ

Frequently Asked Questions about Preview Link Generator