Simple Keyword to Link Security & Risk Analysis

wordpress.org/plugins/simple-keyword-to-link

Really Simple "Keyword to Link" Converter. Automatically create links for specific words in your content

2K active installs v1.5 PHP 7.0+ WP 4.7+ Updated Aug 21, 2024
keywordkeywordslinklink-buildinglinks
48
D · High Risk
CVEs total2
Unpatched2
Last CVEDec 17, 2025
Download
Safety Verdict

Is Simple Keyword to Link Safe to Use in 2026?

High Risk

Score 48/100

Simple Keyword to Link carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.

2 known CVEs 2 unpatched Last CVE: Dec 17, 2025Updated 1yr ago
Risk Assessment

The "simple-keyword-to-link" plugin v1.5 exhibits a mixed security posture. While the static analysis indicates a clean bill of health regarding known dangerous functions, SQL injection vulnerabilities, and taint analysis, suggesting a reasonably secure codebase in its current state for these areas, there are notable weaknesses. Specifically, the plugin has a history of two unpatched medium severity vulnerabilities, both of which were Cross-Site Request Forgery (CSRF) related. The recent nature of the last vulnerability (2025-12-17) is concerning, as it indicates ongoing security challenges or a lack of timely patching by the maintainer. Furthermore, a significant portion of its output is not properly escaped (53%), which could lead to Cross-Site Scripting (XSS) vulnerabilities if data processed by the plugin is not handled carefully by the WordPress theme or other plugins. The absence of capability checks and nonce checks, while not directly flagged as issues by the static analysis, could become points of failure if any new entry points are introduced or if existing ones are exploited in conjunction with other vulnerabilities.

Key Concerns

  • Two unpatched medium CVEs found
  • 53% of output not properly escaped
  • 0 capability checks on entry points
  • 0 nonce checks on entry points
Vulnerabilities
2

Simple Keyword to Link Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-68573medium · 4.3Cross-Site Request Forgery (CSRF)

Simple Keyword to Link <= 1.5 - Cross-Site Request Forgery

Dec 17, 2025Unpatched
CVE-2025-30980medium · 4.3Cross-Site Request Forgery (CSRF)

Simple Keyword to Link <= 1.5 - Cross-Site Request Forgery

Jun 5, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Simple Keyword to Link Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

53% escaped19 total outputs
Attack Surface

Simple Keyword to Link Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filterthe_contentsimple-keyword-to-link.php:18
actionadmin_menusimple-keyword-to-link.php:19
actioninitsimple-keyword-to-link.php:20
actioninitsimple-keyword-to-link.php:22
actiontemplate_redirectsimple-keyword-to-link.php:23
filterquery_varssimple-keyword-to-link.php:24
Maintenance & Trust

Simple Keyword to Link Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 21, 2024
PHP min version7.0
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs2K
Developer Profile

Simple Keyword to Link Developer Profile

Alessandro Piconi

1 plugin · 2K total installs

58
trust score
Avg Security Score
48/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Keyword to Link

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-keyword-to-link/css/simple-keyword-to-link.css/wp-content/plugins/simple-keyword-to-link/js/simple-keyword-to-link.js
Script Paths
/wp-content/plugins/simple-keyword-to-link/js/simple-keyword-to-link.js
Version Parameters
simple-keyword-to-link/css/simple-keyword-to-link.css?ver=simple-keyword-to-link/js/simple-keyword-to-link.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- SE NON FUNZIONA, POTREBBE ESSERE LA CACHE DELLE REWRITE URL, ABILITARE E DISABILITARE IL TIPO DI PERMANLINK --><!-- ottengo i dati associati allo slug --><!-- SCRIVO LA STATS SOLO SE NON È UN BOT --><!-- scrivo un log di testo csv con le info - che poi diventerà qualcosa di più sofisticato o la base di dati per mostrare i dati -->+18 more
Data Attributes
slugSk2L
FAQ

Frequently Asked Questions about Simple Keyword to Link