
TCG Card Links Security & Risk Analysis
wordpress.org/plugins/tcg-card-linksThe goal of this Plug-in is to provide an instantaneous way for you to turn all Magic: the Gathering card names within your blog posts into card infor …
Is TCG Card Links Safe to Use in 2026?
Generally Safe
Score 85/100TCG Card Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'tcg-card-links' plugin version 1.0 exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries are prepared), file operations, and external HTTP requests are strong indicators of secure coding practices. Furthermore, the plugin demonstrates an awareness of WordPress security by implementing capability checks, which are crucial for controlling access to sensitive functionalities. The lack of any known CVEs and a clean vulnerability history is also a significant strength, suggesting a lack of historically exploitable flaws.
However, a critical concern arises from the complete lack of output escaping. With 7 total outputs, the fact that 0% are properly escaped means that any data rendered to the user could potentially be vulnerable to Cross-Site Scripting (XSS) attacks. This is a significant weakness that could allow attackers to inject malicious scripts into the website. Additionally, the absence of nonce checks, while not a direct vulnerability in itself given the low attack surface and capability checks, represents a missed opportunity for further hardening against potential CSRF attacks, especially as the plugin grows.
Key Concerns
- 0% output escaping
- 0 Nonce checks
TCG Card Links Security Vulnerabilities
TCG Card Links Code Analysis
Output Escaping
TCG Card Links Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
TCG Card Links Maintenance & Trust
Maintenance Signals
Community Trust
TCG Card Links Alternatives
CCG Manager
ccg-manager
A WordPress plugin to manage your CCG collection
Temporary Login Without Password
temporary-login-without-password
Create self-expiring, temporary admin accounts. Easily share direct login links (no need for username/password) with your developers or editors.
ImageMagick Engine
imagemagick-engine
Improve the quality of re-sized images by replacing standard GD library with ImageMagick.
Magic Login – Passwordless Authentication for WordPress – Login Without Password
magic-login
Passwordless login for WordPress. Streamline the login process by sending magic links to your users.
ImageMagick Sharpen Resized Images
imagemagick-sharpen-resized-images
Improve your images: Sharpens resized JPG image uploads via ImageMagick so it keeps quality, EXIF information, color profiles and crops.
TCG Card Links Developer Profile
2 plugins · 30 total installs
How We Detect TCG Card Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tcg-card-links/css/jquery.cluetip.css/wp-content/plugins/tcg-card-links/js/jquery.cluetip.min.js/wp-content/plugins/tcg-card-links/js/mtgCardsRef.js/wp-content/plugins/tcg-card-links/js/jquery.cluetip.min.js/wp-content/plugins/tcg-card-links/js/mtgCardsRef.js/tcg-card-links/css/jquery.cluetip.css?ver=/tcg-card-links/js/jquery.cluetip.min.js?ver=/tcg-card-links/js/mtgCardsRef.js?ver=HTML / DOM Fingerprints
mtgcardref_rollover<a class="mtgcardref_rollover" href=