Traction External Links Speed Bump Security & Risk Analysis

wordpress.org/plugins/traction-external-links-speed-bump

Activates a speed bump on all external links and gives site owner the ability to enter a list of domains or specific links that when clicked will not …

100 active installs v1.9.8 PHP + WP 3.0.1+ Updated Jul 7, 2025
complianceexternal-linksspeed-bumptraction
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Traction External Links Speed Bump Safe to Use in 2026?

Generally Safe

Score 100/100

Traction External Links Speed Bump has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The security posture of the "traction-external-links-speed-bump" v1.9.8 plugin appears to be generally strong based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, significantly limiting the potential attack surface. The code also demonstrates good practices by using prepared statements for all SQL queries, having no file operations or external HTTP requests, and including nonce and capability checks. However, a significant concern arises from the low percentage of properly escaped output (38%). This suggests that a substantial portion of user-supplied data, if processed by the plugin and then displayed, could be vulnerable to Cross-Site Scripting (XSS) attacks. Despite the absence of known CVEs and a clean vulnerability history, the output escaping deficiency represents a tangible risk that could be exploited. The lack of taint analysis results is noted, but it doesn't negate the direct evidence of insufficient output sanitization.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Traction External Links Speed Bump Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Traction External Links Speed Bump Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
6 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped16 total outputs
Attack Surface

Traction External Links Speed Bump Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menutraction-external-links-speed-bump.php:48
actionwp_enqueue_scriptstraction-external-links-speed-bump.php:250
Maintenance & Trust

Traction External Links Speed Bump Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 7, 2025
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings4
Active installs100
Developer Profile

Traction External Links Speed Bump Developer Profile

Traction

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Traction External Links Speed Bump

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/traction-external-links-speed-bump/css/traction-external-links-speed-bump.css
Script Paths
/wp-content/plugins/traction-external-links-speed-bump/js/traction-external-links-speed-bump.js
Version Parameters
traction-external-links-speed-bump/css/traction-external-links-speed-bump.css?ver=traction-external-links-speed-bump/js/traction-external-links-speed-bump.js?ver=

HTML / DOM Fingerprints

JS Globals
trelsb_php_vars
FAQ

Frequently Asked Questions about Traction External Links Speed Bump