
Rotating Links Widget Security & Risk Analysis
wordpress.org/plugins/rotating-links-widgetThis plugin add widget which displays random links on your website.
Is Rotating Links Widget Safe to Use in 2026?
Generally Safe
Score 85/100Rotating Links Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rotating-links-widget" plugin version 0.1 presents a mixed security posture. On the positive side, it has a very small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are not properly secured. Furthermore, all identified SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are common vectors for exploitation. The lack of any recorded vulnerabilities in its history is also a good sign.
However, significant concerns exist due to specific code signals. The presence of the `create_function` function is a critical red flag, as it is deprecated and considered insecure due to potential for arbitrary code execution if used with user-supplied input. Additionally, the output escaping is very poor, with only 31% of outputs properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks across all entry points, combined with the identified use of `create_function` and poor output escaping, creates a dangerous environment for potential attacks.
In conclusion, while the plugin benefits from a limited attack surface and secure SQL practices, the insecure use of `create_function` and widespread lack of output escaping represent severe security weaknesses that outweigh its strengths. The absence of past vulnerabilities might be due to the plugin's obscurity or limited usage, rather than inherent robust security.
Key Concerns
- Use of create_function
- Poor output escaping
- Missing nonce checks
- Missing capability checks
Rotating Links Widget Security Vulnerabilities
Rotating Links Widget Release Timeline
Rotating Links Widget Code Analysis
Dangerous Functions Found
Output Escaping
Rotating Links Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Rotating Links Widget Maintenance & Trust
Maintenance Signals
Community Trust
Rotating Links Widget Alternatives
Link Manager
link-manager
Enables the Link Manager that existed in WordPress until version 3.5.
Random Content
random-content
Display random content anywhere on your WordPress site. Rotate testimonials, banners, CTAs, and more with a simple shortcode or widget.
Eazy Enable Blogroll
eazy-enable-blogroll
Eazy Enable Blogroll brings back the one and only WordPress Blogroll Feature, with nearly one click!
Link View
link-view
Display a link-list or link-slider in a post or page by using a shortcode.
Better Blogroll
better-blogroll
Allows you to display a configurable number of random links from your Wordpress blogroll
Rotating Links Widget Developer Profile
8 plugins · 140 total installs
How We Detect Rotating Links Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
rotlinkcatid="rotate_links-'