BlogWell's Simple Image Link Widget Security & Risk Analysis

wordpress.org/plugins/simple-image-link

A widget which allows you to add an image with a link to your sidebar.

400 active installs v2.2.2 PHP + WP 2.8+ Updated Oct 1, 2009
advertisementimagelinksponsorshipwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BlogWell's Simple Image Link Widget Safe to Use in 2026?

Generally Safe

Score 85/100

BlogWell's Simple Image Link Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The "simple-image-link" plugin version 2.2.2 exhibits a strong security posture concerning its attack surface and handling of SQL queries, as it reports zero entry points and all SQL queries utilize prepared statements. The absence of known vulnerabilities (CVEs) and a clean vulnerability history further suggests a history of stable and secure development. However, a significant concern arises from the static analysis indicating that 90 output operations are not properly escaped. This widespread lack of output escaping presents a considerable risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data displayed on the front-end could be manipulated to inject malicious scripts. While the plugin demonstrates good practices in other areas, this single weakness in output sanitization warrants attention and is the primary area of concern.

Key Concerns

  • 90 outputs not properly escaped
Vulnerabilities
None known

BlogWell's Simple Image Link Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BlogWell's Simple Image Link Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
90
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped90 total outputs
Attack Surface

BlogWell's Simple Image Link Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwidgets_initsimple-image-link.php:391
actionwp_headsimple-image-link.php:393
actionadmin_headsimple-image-link.php:394
Maintenance & Trust

BlogWell's Simple Image Link Widget Maintenance & Trust

Maintenance Signals

WordPress version tested2.8.4
Last updatedOct 1, 2009
PHP min version
Downloads42K

Community Trust

Rating0/100
Number of ratings0
Active installs400
Developer Profile

BlogWell's Simple Image Link Widget Developer Profile

Martyn Davis

1 plugin · 400 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BlogWell's Simple Image Link Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-image-link/simple-image-link.css

HTML / DOM Fingerprints

CSS Classes
simpleimagelinkwidget_simpleimagelink_containerwidget_simpleimagelink
HTML Comments
<!-- ImageLink widget -->
Data Attributes
data-widget_simpleimagelink_id
FAQ

Frequently Asked Questions about BlogWell's Simple Image Link Widget