
Preview Site for WordPress Admin Security & Risk Analysis
wordpress.org/plugins/preview-site-linkPreview site for WordPress Admin
Is Preview Site for WordPress Admin Safe to Use in 2026?
Generally Safe
Score 85/100Preview Site for WordPress Admin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "preview-site-link" v1.0 plugin exhibits a strong security posture regarding its attack surface and SQL injection vulnerabilities, as evidenced by the absence of AJAX handlers, REST API routes, shortcodes, and cron events. The code also demonstrates good practice by exclusively using prepared statements for its SQL queries, which is a significant mitigation against SQL injection risks. The lack of file operations and external HTTP requests further reduces potential attack vectors.
However, a notable concern is the complete lack of output escaping. With two outputs analyzed and 0% properly escaped, this presents a significant risk for cross-site scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the front-end without proper sanitization can be exploited by attackers. Additionally, the absence of nonce and capability checks, while not directly tied to a revealed attack surface in this analysis, is a critical weakness for any plugin that might interact with user actions or sensitive data in the future.
The plugin's vulnerability history is clean, with no known CVEs. This, combined with the lack of critical taint analysis findings, suggests that at present, there are no publicly known or discoverable critical security flaws. However, the absence of past vulnerabilities can sometimes indicate a small user base or limited historical analysis, rather than an inherently secure plugin, especially in light of the identified output escaping and authorization weaknesses.
Key Concerns
- 0% output escaping
- No nonce checks
- No capability checks
Preview Site for WordPress Admin Security Vulnerabilities
Preview Site for WordPress Admin Code Analysis
Output Escaping
Preview Site for WordPress Admin Attack Surface
WordPress Hooks 3
Maintenance & Trust
Preview Site for WordPress Admin Maintenance & Trust
Maintenance Signals
Community Trust
Preview Site for WordPress Admin Alternatives
Preview Site for WordPress Admin Developer Profile
1 plugin · 10 total installs
How We Detect Preview Site for WordPress Admin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
preview-site-for-wordpress-admin-v1.0HTML / DOM Fingerprints
main<a id='main' href='