
The Permalinker Security & Risk Analysis
wordpress.org/plugins/the-permalinkerUse short codes to dynamically link to your WordPress pages and posts. All you need is the ID. This can come in handy when developing content for Word …
Is The Permalinker Safe to Use in 2026?
Generally Safe
Score 91/100The Permalinker has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of 'the-permalinker' v1.9.0 reveals a strong security posture in terms of common web vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates good practices by using prepared statements for all SQL queries and properly escaping all outputs. There are no identified dangerous functions, file operations, external HTTP requests, or bundled libraries that might pose a risk. Taint analysis also found no issues, indicating no obvious vulnerabilities related to unsanitized data flows.
However, the plugin's vulnerability history presents a significant concern. It has one known CVE, though it is currently unpatched. This past vulnerability was a medium severity Cross-site Scripting (XSS) issue, indicating a potential for attackers to inject malicious scripts. While no XSS is detected in the current version through static analysis, the historical presence of such a vulnerability suggests a latent risk. The absence of nonce checks and capability checks across its limited entry points, while seemingly safe due to the lack of entry points, could become a weakness if new entry points are added in future versions without proper security considerations.
In conclusion, 'the-permalinker' v1.9.0 exhibits excellent coding practices in its current state, with no exploitable vulnerabilities found during static analysis. Its limited attack surface further bolsters its security. The primary weakness lies in its past vulnerability history, specifically a medium severity XSS, and the lack of explicit authorization checks, which, while not an immediate threat given the current state, warrants caution for future development.
Key Concerns
- Unpatched CVE present
- Medium severity vulnerability in history
- No nonce checks on entry points
- No capability checks on entry points
The Permalinker Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
The Permalinker <= 1.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Permalinker Code Analysis
The Permalinker Attack Surface
Maintenance & Trust
The Permalinker Maintenance & Trust
Maintenance Signals
Community Trust
The Permalinker Alternatives
Backup Migration
backup-backup
Backup Migration
WP STAGING – WordPress Backup, Restore & Migration
wp-staging
Backup, restore, staging, and migration for WordPress. Create full-site backups and test updates safely.
BlogVault Backup & Staging
blogvault-real-time-backup
Secure incremental backups with staging, migration, and one-click restore for WordPress. Offsite storage and easy recovery.
Backup and Staging by WP Time Capsule
wp-time-capsule
Backup and Staging by WP Time Capsule is an automated incremental backup plugin that backs up your website changes as per your schedule to Dropbox, Go …
Monkeyman Rewrite Analyzer
monkeyman-rewrite-analyzer
Making sense of the rewrite mess. Display and play with your rewrite rules.
The Permalinker Developer Profile
4 plugins · 2K total installs
How We Detect The Permalinker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
permalinker_link[permalink][template_uri]