Remove Link URL Security & Risk Analysis

wordpress.org/plugins/remove-link-url

This plugin removes the Link URL that is enabled by default when images are uploaded to your WordPress blog.

100 active installs v1.0 PHP + WP 2.5+ Updated Jan 24, 2012
adminlinksmediauploadwillshouse
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Remove Link URL Safe to Use in 2026?

Generally Safe

Score 85/100

Remove Link URL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The 'remove-link-url' plugin version 1.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries not using prepared statements, unescaped output, file operations, or external HTTP requests suggests diligent coding practices. Furthermore, the zero count for critical and high severity taint flows indicates a lack of easily exploitable input sanitization issues. The plugin also has no recorded vulnerabilities, either historical or current, which further reinforces its apparent security.

However, the analysis also reveals a complete lack of security checks for its entry points. With zero AJAX handlers, REST API routes, shortcodes, or cron events, the plugin has no demonstrable attack surface to secure. While this means there are no *unprotected* entry points, it also implies a potential for issues if functionality were to be added in the future without proper authentication or authorization checks. The absence of nonce and capability checks on all entry points is a significant gap, even in the absence of current threats. This lack of fundamental security controls presents a foundational weakness that could become problematic if the plugin evolves.

In conclusion, the 'remove-link-url' plugin 1.0 currently appears very secure due to its minimal functionality and the absence of known vulnerabilities and exploitable code patterns. Its strengths lie in its clean code and lack of any detected critical security flaws. The primary weakness is the absence of any security checks on its non-existent entry points, which, while not a direct vulnerability now, represents a missed opportunity for best practice implementation and a potential future risk.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
Vulnerabilities
None known

Remove Link URL Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Remove Link URL Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Remove Link URL Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitremove-link-url.php:18
filterattachment_fields_to_editremove-link-url.php:23
Maintenance & Trust

Remove Link URL Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedJan 24, 2012
PHP min version
Downloads12K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Remove Link URL Developer Profile

willshouse

3 plugins · 5K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Remove Link URL

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Remove Link URL