
Send link to friend Security & Risk Analysis
wordpress.org/plugins/send-link-to-friendIf user think the content is useful to their friend, they can use this form to send the URL instead of copy and paste the URL into email.
Is Send link to friend Safe to Use in 2026?
Generally Safe
Score 85/100Send link to friend has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'send-link-to-friend' plugin version 12.4 exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and having no recorded vulnerability history, there are significant concerns regarding its attack surface and output escaping. The presence of two AJAX handlers without authentication checks presents a direct entry point for potential attacks, especially if these handlers perform sensitive operations. Furthermore, the low percentage of properly escaped output (20%) suggests a high risk of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site. The taint analysis, while not revealing critical or high severity issues, did identify unsanitized paths, which warrants attention. In conclusion, the plugin's lack of historical vulnerabilities is a positive sign, but the identified code weaknesses in handling AJAX requests and output escaping create notable security risks that should be addressed.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of properly escaped output
- Flows with unsanitized paths
Send link to friend Security Vulnerabilities
Send link to friend Code Analysis
Output Escaping
Data Flow Analysis
Send link to friend Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Send link to friend Maintenance & Trust
Maintenance Signals
Community Trust
Send link to friend Alternatives
No alternatives data available yet.
Send link to friend Developer Profile
52 plugins · 19K total installs
How We Detect Send link to friend
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/send-link-to-friend/css/style.css/wp-content/plugins/send-link-to-friend/js/send-link-to-friend.js/wp-content/plugins/send-link-to-friend/js/send-link-to-friend.jssend-link-to-friend/css/style.css?ver=send-link-to-friend/js/send-link-to-friend.js?ver=HTML / DOM Fingerprints
gSendtofriendgSendtofriend_form_submitgSendtofriend_submitgSendtofriend_fromnamegSendtofriend_fromemailgSendtofriend_mailcontentgSendtofriend_subject+10 more