Super Link Preview Security & Risk Analysis

wordpress.org/plugins/super-link-preview

Get the most relevant image, or the appropriate embedded media player, or the page screenshot of any external link in your post (similar to what you g …

70 active installs v1.0.1 PHP + WP 3.3.0+ Updated Dec 3, 2014
browserbrowser-shotgeneratorscreenshottool
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Super Link Preview Safe to Use in 2026?

Generally Safe

Score 85/100

Super Link Preview has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "super-link-preview" plugin v1.0.1 exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and a zero-day history indicates a history of responsible development or minimal attack targets. Furthermore, the complete lack of dangerous functions, SQL queries without prepared statements, and zero taint flows suggest a strong foundation against common vulnerabilities.

However, there are areas for improvement. The output escaping rate of 43% is a significant concern, as unescaped output can lead to Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is involved in these outputs. While the plugin has no reported vulnerabilities, this lack of past issues could also imply limited scrutiny or testing. The absence of nonce checks on any entry points, while not explicitly flagged as an issue due to the zero attack surface, could become a risk if new entry points are added without proper authentication and authorization checks.

In conclusion, the plugin has strengths in its sanitized query handling and lack of critical code signals. The primary weakness lies in the insufficient output escaping, which warrants attention to prevent potential XSS flaws. The plugin's clean historical record is positive but should not lead to complacency. Proactive code reviews focusing on output sanitization would greatly enhance its security.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Super Link Preview Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Super Link Preview Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Super Link Preview Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
6 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

43% escaped14 total outputs
Attack Surface

Super Link Preview Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitsuper-link-preview.php:34
actionsave_postsuper-link-preview.php:35
actionwp_enqueue_scriptssuper-link-preview.php:37
actionadmin_menusuper-link-preview.php:38
actionadmin_initsuper-link-preview.php:39
filtermce_external_pluginssuper-link-preview.php:524
filtermce_buttonssuper-link-preview.php:525
Maintenance & Trust

Super Link Preview Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedDec 3, 2014
PHP min version
Downloads6K

Community Trust

Rating94/100
Number of ratings3
Active installs70
Developer Profile

Super Link Preview Developer Profile

Daniele Perilli

1 plugin · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Super Link Preview

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/super-link-preview/js/script.js
Script Paths
/wp-content/plugins/super-link-preview/js/script.js
Version Parameters
super-link-preview/js/script.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Use for testing - Leave blank -->
Data Attributes
name="super-link-preview_img_min_width"name="super-link-preview_img_min_height"name="super-link-preview_img_disallow_ads"name="super-link-preview_img_og_meta"name="super-link-preview_auto_embed"name="super-link-preview_shot_service"
Shortcode Output
[link-preview url="external_link"]
FAQ

Frequently Asked Questions about Super Link Preview