
Simple Link Directory Security & Risk Analysis
wordpress.org/plugins/simple-link-directoryFree LINK DIRECTORY Plugin for WordPress to Curate Links for Web Directory. Link management, Directory Listings, Link Archive, Vendor Directory
Is Simple Link Directory Safe to Use in 2026?
Generally Safe
Score 86/100Simple Link Directory has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'simple-link-directory' v8.8.7 exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of SQL prepared statements and properly escaped output, there are significant concerns that temper its overall safety.
The static analysis reveals an attack surface of 14 entry points, with one AJAX handler notably lacking authentication checks. This unsupervised entry point is a direct pathway for potential exploitation. Furthermore, the taint analysis identified one high-severity flow with unsanitized paths, suggesting a potential for code injection or similar vulnerabilities that could compromise the application.
The plugin's vulnerability history is a major red flag. With 6 known CVEs, including one critical and one high severity, even though none are currently unpatched, the pattern of past vulnerabilities points to recurring security weaknesses. The types of past vulnerabilities (CSRF, Missing Authorization, Code Injection, SQL Injection, XSS, Deserialization) indicate a history of mishandling user input and authorization. While the plugin has a recent vulnerability date of 2025-12-15, this could indicate ongoing research or that the data is from a future perspective. The overall picture is one of a plugin that has had significant security issues in the past, and while current analysis shows some improvements, the history warrants caution. The presence of the unauthenticated AJAX handler and the high-severity taint flow are immediate risks that need addressing.
Key Concerns
- Unprotected AJAX handler
- High severity unsanitized path taint flow
- History of critical vulnerabilities
- History of high severity vulnerabilities
Simple Link Directory Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Simple Link Directory <= 8.8.3 - Cross-Site Request Forgery
Simple Link Directory <= 8.8.3 - Missing Authorization
Simple Link Directory <= 8.4.5 - Unauthenticated Arbitrary Shortcode Execution
Simple Link Directory <= 7.7.1 - Unauthenticated SQL Injection
Simple Link Directory < 7.3.5 - Reflected Cross-Site Scripting
Simple Link Directory <= 5.6.0 - PHP Object Injection
Simple Link Directory Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Simple Link Directory Attack Surface
AJAX Handlers 13
Shortcodes 1
WordPress Hooks 62
Maintenance & Trust
Simple Link Directory Maintenance & Trust
Maintenance Signals
Community Trust
Simple Link Directory Alternatives
WP Links Page
wp-links-page
This plugin allows you to create a dynamic link gallery with screenshots of each link.
DirectoryPress Frontend
directorypress-frontend
This plugin provides frontend listing functionality for [DirectoryPress - Directory Listing Plugin](https://designinvento.
DirectoryPress – Business Directory And Classified Ad Listing
directorypress
DirectoryPress is most advanced and flexible directory listing plugin with wide range of features, You can build a business directory, classified list …
aDirectory – WP Business Directory Plugin and Classified Ads Listings Directory
adirectory
aDirectory is a lightweight, scalable, fast WordPress directory plugin for building any type of directories, classifieds, and job boards websites.
Disable Directory Listings
disable-directory-listings
Prevent virtual directory listing services from listing the contents of directories, and/or show a page in place of a directory's listing.
Simple Link Directory Developer Profile
29 plugins · 26K total installs
How We Detect Simple Link Directory
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-link-directory/assets/css/sld-admin-style.css/wp-content/plugins/simple-link-directory/assets/css/sld-frontend.css/wp-content/plugins/simple-link-directory/assets/js/sld-frontend-script.js/wp-content/plugins/simple-link-directory/assets/js/slick.min.js/wp-content/plugins/simple-link-directory/assets/js/jqc-slick.min.js/wp-content/plugins/simple-link-directory/embed/js/embedder.js/wp-content/plugins/simple-link-directory/assets/js/sld-frontend-script.js/wp-content/plugins/simple-link-directory/assets/js/slick.min.js/wp-content/plugins/simple-link-directory/assets/js/jqc-slick.min.js/wp-content/plugins/simple-link-directory/embed/js/embedder.jssimple-link-directory/assets/css/sld-admin-style.css?ver=simple-link-directory/assets/css/sld-frontend.css?ver=simple-link-directory/assets/js/sld-frontend-script.js?ver=simple-link-directory/assets/js/slick.min.js?ver=simple-link-directory/assets/js/jqc-slick.min.js?ver=simple-link-directory/embed/js/embedder.js?ver=HTML / DOM Fingerprints
qcsld-promo-linksld-noticesld_info_carouselsld_info_item/*01-27-2026*//*05-31-2017*//*05-31-2017 - Ends*//* Option page */+1 moredata-post_type="sld"QCOPD_URLQCOPD_IMG_URLQCOPD_ASSETS_URLQCOPD_DIRQCOPD_INC_DIROCOPD_TPL_URL+2 more<a href="https://www.quantumcloud.com/products/simple-link-directory/" target="_blank" class="button qcsld-promo-link">Upgrade to Pro</a><a href="" class="button">Add New List of Links</a>**SLD Pro Tip: Did you know that you can