WAJ Links Security & Risk Analysis

wordpress.org/plugins/waj-links

Way to mo'-easily create links o' various types in content through PHP & shortcodes.

0 active installs v1.3.0 PHP 7.0+ WP 4.9.8+ Updated May 8, 2019
auto-generatehtmllink
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WAJ Links Safe to Use in 2026?

Generally Safe

Score 85/100

WAJ Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of the "waj-links" v1.3.0 plugin reveals a generally strong security posture. The plugin demonstrates good practice by not utilizing dangerous functions, all SQL queries are prepared statements, and all outputs are properly escaped. Furthermore, there are no observed file operations or external HTTP requests, which significantly reduces potential attack vectors. The absence of known vulnerabilities in its history is also a positive indicator of its current security status.

However, the plugin does present a moderate attack surface through its eight shortcodes, none of which have explicit capability checks or nonce validation indicated in the static analysis. While the absence of taint flows and dangerous functions mitigates the immediate risk from these shortcodes, any future development or modification that involves user-supplied input processed by these shortcodes without proper sanitization or authorization could introduce vulnerabilities. The lack of observed nonce checks across all entry points, including shortcodes, is a notable weakness that could be exploited if functionality is sensitive or processes untrusted data.

In conclusion, "waj-links" v1.3.0 is currently in a good security state due to its clean code and lack of historical vulnerabilities. The primary concern lies in the potential for future vulnerabilities arising from the shortcode functionality lacking explicit authorization checks. Addressing this by implementing capability checks and nonce validation for all shortcodes would further strengthen its security.

Key Concerns

  • Shortcodes lack capability checks
  • Shortcodes lack nonce checks
Vulnerabilities
None known

WAJ Links Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WAJ Links Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WAJ Links Attack Surface

Entry Points8
Unprotected0

Shortcodes 8

[link] waj-links.php:27
[mail-link] waj-links.php:40
[post-link] waj-links.php:56
[category-link] waj-links.php:71
[tag-link] waj-links.php:86
[home-link] waj-links.php:101
[phone-link] waj-links.php:115
[media-link] waj-links.php:131
Maintenance & Trust

WAJ Links Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedMay 8, 2019
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WAJ Links Developer Profile

waughjai

4 plugins · 10 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WAJ Links

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/waj-links/

HTML / DOM Fingerprints

Shortcode Output
[link [mail-link [post-link [category-link
FAQ

Frequently Asked Questions about WAJ Links