
Show Links Security & Risk Analysis
wordpress.org/plugins/showlinksA small plugin whose only purpose is to show links added with the Dashboard, using a shortcode.
Is Show Links Safe to Use in 2026?
Generally Safe
Score 85/100Show Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'showlinks' plugin v1.02 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and proper output escaping indicate good development practices. Furthermore, the plugin's attack surface is minimal, consisting of a single shortcode, and importantly, there are no identified AJAX handlers or REST API routes that lack authentication checks. The lack of any recorded vulnerabilities or CVEs further strengthens this positive assessment. The taint analysis also shows no concerning flows, suggesting data is handled securely.
While the plugin demonstrates an excellent foundation in secure coding, the primary area for consideration lies in the complete absence of nonce checks and capability checks. Although the current attack surface is small and appears to be handled without authentication issues, any expansion of functionality or introduction of new entry points without these crucial security measures could introduce significant risks. The vulnerability history is a strong positive, indicating a history of secure development, but it's essential to maintain this vigilance. Overall, the plugin is secure based on current analysis, but future development should incorporate nonce and capability checks to solidify its security.
Key Concerns
- Missing nonce checks
- Missing capability checks
Show Links Security Vulnerabilities
Show Links Code Analysis
Show Links Attack Surface
Shortcodes 1
Maintenance & Trust
Show Links Maintenance & Trust
Maintenance Signals
Community Trust
Show Links Alternatives
Abdiel Global Variables
abdiel-global-variables
Create reusable global text values (phones, links, short messages, custom values, etc.) and use them anywhere via simple shortcodes.
Automatic Domain Changer
automatic-domain-changer
Automatically detects a domain name change, and updates all the WordPress tables in the database to reflect this change.
Root Relative URLs
root-relative-urls
Converts all URLs to root-relative URLs for hosting the same site on multiple IPs, easier production migration and better mobile device testing.
Admin Collapse Subpages
admin-collapse-subpages
Using this plugin one can easily collapse/expand pages with children and grand children.
Yada Wiki
yada-wiki
Yada Wiki is a simple wiki for your WordPress site.
Show Links Developer Profile
3 plugins · 30 total installs
How We Detect Show Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[showlinks]