Preview Site for WordPress Admin Security & Risk Analysis

wordpress.org/plugins/preview-site-link

Preview site for WordPress Admin

10 active installs v1.0 PHP + WP 2.8+ Updated Jan 20, 2013
preview-sitepreview-site-adminpreview-site-wordpress-adminvisit-sitevisit-site-link
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Preview Site for WordPress Admin Safe to Use in 2026?

Generally Safe

Score 85/100

Preview Site for WordPress Admin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "preview-site-link" v1.0 plugin exhibits a strong security posture regarding its attack surface and SQL injection vulnerabilities, as evidenced by the absence of AJAX handlers, REST API routes, shortcodes, and cron events. The code also demonstrates good practice by exclusively using prepared statements for its SQL queries, which is a significant mitigation against SQL injection risks. The lack of file operations and external HTTP requests further reduces potential attack vectors.

However, a notable concern is the complete lack of output escaping. With two outputs analyzed and 0% properly escaped, this presents a significant risk for cross-site scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the front-end without proper sanitization can be exploited by attackers. Additionally, the absence of nonce and capability checks, while not directly tied to a revealed attack surface in this analysis, is a critical weakness for any plugin that might interact with user actions or sensitive data in the future.

The plugin's vulnerability history is clean, with no known CVEs. This, combined with the lack of critical taint analysis findings, suggests that at present, there are no publicly known or discoverable critical security flaws. However, the absence of past vulnerabilities can sometimes indicate a small user base or limited historical analysis, rather than an inherently secure plugin, especially in light of the identified output escaping and authorization weaknesses.

Key Concerns

  • 0% output escaping
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Preview Site for WordPress Admin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Preview Site for WordPress Admin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Preview Site for WordPress Admin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_headpreview-site-for-wordpress-admin.php:41
actionadmin_headpreview-site-for-wordpress-admin.php:42
actionadmin_noticespreview-site-for-wordpress-admin.php:43
Maintenance & Trust

Preview Site for WordPress Admin Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedJan 20, 2013
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Preview Site for WordPress Admin Developer Profile

samratshamim

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Preview Site for WordPress Admin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Generator Patterns
preview-site-for-wordpress-admin-v1.0

HTML / DOM Fingerprints

CSS Classes
main
Shortcode Output
<a id='main' href='
FAQ

Frequently Asked Questions about Preview Site for WordPress Admin