
Pz-LinkCard Security & Risk Analysis
wordpress.org/plugins/pz-linkcardThis plugin is intended to display a link in a blog card format. The goodbye to the text-only link.
Is Pz-LinkCard Safe to Use in 2026?
Generally Safe
Score 96/100Pz-LinkCard has a strong security track record. Known vulnerabilities have been patched promptly.
The "pz-linkcard" plugin version 2.5.8.1 exhibits a mixed security posture. On the positive side, static analysis reveals a very small attack surface with no unprotected entry points, robust use of prepared statements for SQL queries, and excellent output escaping. Taint analysis also shows no critical or high severity issues related to unsanitized paths.
However, the plugin's vulnerability history is a significant concern. With six known medium-severity vulnerabilities, including historical instances of SSRF, CSRF, and XSS, it indicates a recurring pattern of insecure coding practices that have led to exploitable flaws. The fact that the last vulnerability was only recently discovered (2025-09-23) suggests that while they may be currently patched, the underlying issues are still present in the codebase. The absence of capability checks on its entry points, despite having AJAX handlers, is also a potential area for further investigation and hardening.
In conclusion, while the current version of "pz-linkcard" appears to have addressed immediate critical threats and demonstrates good practices in SQL and output handling, its past vulnerability record necessitates caution. Users should be aware of the historical susceptibility of this plugin, and developers should prioritize a thorough review of the codebase to prevent recurrence of past vulnerability types. The lack of capability checks is a notable weakness.
Key Concerns
- History of medium vulnerabilities (6 total)
- No capability checks on entry points
- Limited nonce checks (1)
Pz-LinkCard Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Pz-LinkCard <= 2.5.6 - Authenticated (Contributor+) Server-Side Request Forgery
Pz-LinkCard <= 2.5.2 - Sever-Side Request Forgery
Pz-LinkCard <= 2.5.2 - Reflected Cross-Site Scripting
Pz-LinkCard <= 2.5.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Pz-LinkCard <= 2.5.2 - Cross-Site Request Forgery via page_cacheman
Pz-LinkCard <= 2.4.5.1 - Reflected Cross-Site Scripting
Pz-LinkCard Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Pz-LinkCard Attack Surface
AJAX Handlers 2
WordPress Hooks 15
Maintenance & Trust
Pz-LinkCard Maintenance & Trust
Maintenance Signals
Community Trust
Pz-LinkCard Alternatives
Simple Blog Card
simple-blog-card
Get OGP and display blog card.
Broken Link Checker
broken-link-checker
Broken Link Checker helps you catch broken links & images fast, before they hurt your SEO or UX. Scan and bulk-fix issues from one easy dashboard.
Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links
broken-link-checker-seo
Broken Link Checker by AIOSEO ensures all links on your website are working. Check your site for broken links and easily fix them to improve SEO.
Pz-HatenaBlogCard
pz-hatenablogcard
This plug-in to display a link in the article by using the "Hatena blog card".
anyLink
anylink
AnyLink is a Wordpress plugin which allow you to customise you external link like an internal one.
Pz-LinkCard Developer Profile
4 plugins · 20K total installs
How We Detect Pz-LinkCard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pz-linkcard/assets/css/pz-linkcard.css/wp-content/plugins/pz-linkcard/assets/js/pz-linkcard.js/wp-content/plugins/pz-linkcard/assets/js/pz-linkcard.jspz-linkcard/assets/css/pz-linkcard.css?ver=pz-linkcard/assets/js/pz-linkcard.js?ver=HTML / DOM Fingerprints
pz-linkcardpz_linkcard_setting[pz-linkcard[/pz-linkcard]