
VerseLinker Security & Risk Analysis
wordpress.org/plugins/verselinkerVerseLinker detects Bible references in WordPress content, converting them into links with tooltips and quick access to verses on Bibliatodo.com.
Is VerseLinker Safe to Use in 2026?
Generally Safe
Score 100/100VerseLinker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "verselinker" plugin v1.1.9 demonstrates a strong security posture based on the provided static analysis. The absence of identified dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests are positive indicators. The high percentage of properly escaped output also suggests good practices in preventing cross-site scripting (XSS) vulnerabilities. The plugin has a limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks.
However, the analysis does reveal some areas for concern. The complete lack of taint analysis results could indicate that no taint analysis was performed, or that the tools used did not identify any flows. Without this analysis, there's a blind spot regarding potential vulnerabilities that might arise from the interaction of user-supplied data with potentially vulnerable functions, even if those functions aren't explicitly flagged as "dangerous". Furthermore, the fact that there are zero nonce checks across the entire plugin, despite having one capability check, is a significant weakness. This suggests that any function that relies on this capability check might still be vulnerable to unauthorized access or execution if an attacker can forge requests without a valid nonce.
The plugin's vulnerability history is a significant strength, showing zero known CVEs. This, combined with the static analysis, indicates a well-maintained and likely secure codebase. However, it's important to remember that a clean history doesn't guarantee future security, and the presence of the nonce check gap is a notable weakness that should be addressed. The overall security is good, but the lack of nonce checks on potentially sensitive operations is a clear area for improvement.
Key Concerns
- Missing nonce checks
VerseLinker Security Vulnerabilities
VerseLinker Code Analysis
Output Escaping
VerseLinker Attack Surface
WordPress Hooks 8
Maintenance & Trust
VerseLinker Maintenance & Trust
Maintenance Signals
Community Trust
VerseLinker Alternatives
Logos Reftagger
reftagger
Logos Reftagger turns Bible references into links to the verse on Biblia.com and adds tooltips with the text of the verse.
Predikarens bibelreferenser
predikarens-bibelreferenser
This plugin uses the biblegateway.com servers and a modified version of their public javascript to display Bible reference content in Swedish.
RefTagger Toggle
reftagger-toggle
Allows disabling Reftagger on a per-page/post basis.
Bible Verse of the Day
bible-verse-of-the-day
Shows the daily inspiring Bible verse or a random Bible verse from DailyVerses.net. In English, Spanish, Portuguese, German, French, Italian, Polish, …
Visual Bible Verse of the Day Widget
visual-verse-of-the-day-widget
Six days a week a new photo and scripture reference will appear from The Visual Bible Verse of the Day at visualverse.thecreationspeaks.com.
VerseLinker Developer Profile
8 plugins · 150 total installs
How We Detect VerseLinker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/verselinker/assets/js/verselinker.js/wp-content/plugins/verselinker/assets/js/admin-script.js/wp-content/plugins/verselinker/assets/js/verselinker.js/wp-content/plugins/verselinker/assets/js/admin-script.js/wp-content/plugins/verselinker/assets/js/verselinker.js?ver=/wp-content/plugins/verselinker/assets/js/admin-script.js?ver=HTML / DOM Fingerprints
langversiondata-trueTooltipdata-trueCreditdata-trueLinksverselinkerData