
WAJ Links Security & Risk Analysis
wordpress.org/plugins/waj-linksWay to mo'-easily create links o' various types in content through PHP & shortcodes.
Is WAJ Links Safe to Use in 2026?
Generally Safe
Score 85/100WAJ Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "waj-links" v1.3.0 plugin reveals a generally strong security posture. The plugin demonstrates good practice by not utilizing dangerous functions, all SQL queries are prepared statements, and all outputs are properly escaped. Furthermore, there are no observed file operations or external HTTP requests, which significantly reduces potential attack vectors. The absence of known vulnerabilities in its history is also a positive indicator of its current security status.
However, the plugin does present a moderate attack surface through its eight shortcodes, none of which have explicit capability checks or nonce validation indicated in the static analysis. While the absence of taint flows and dangerous functions mitigates the immediate risk from these shortcodes, any future development or modification that involves user-supplied input processed by these shortcodes without proper sanitization or authorization could introduce vulnerabilities. The lack of observed nonce checks across all entry points, including shortcodes, is a notable weakness that could be exploited if functionality is sensitive or processes untrusted data.
In conclusion, "waj-links" v1.3.0 is currently in a good security state due to its clean code and lack of historical vulnerabilities. The primary concern lies in the potential for future vulnerabilities arising from the shortcode functionality lacking explicit authorization checks. Addressing this by implementing capability checks and nonce validation for all shortcodes would further strengthen its security.
Key Concerns
- Shortcodes lack capability checks
- Shortcodes lack nonce checks
WAJ Links Security Vulnerabilities
WAJ Links Code Analysis
WAJ Links Attack Surface
Shortcodes 8
Maintenance & Trust
WAJ Links Maintenance & Trust
Maintenance Signals
Community Trust
WAJ Links Alternatives
Append extensions on Pages
append-extensions-on-pages
This plugin helps to appends .html or .asp or .htm etc on the wordpress pages when used with permalink.
SEO Internal Link Shortcode
seo-internal-link-shortcode
Internal links to posts, custom-type posts, pages, categories and tags with any HTML attribute(s).
Twitter Wings
twitter-wings
An easy to configure Twitter Plugin with Pretty URLs.
Embed bare image links
embed-bare-image-links
Converts bare image links inserted in the post content by the user into HTML tagged images, so turns links into visible images.
LH Paragraph Ids
lh-paragraph-ids
LH Paragraph Ids is a WordPress plugin that adds ids to paragraph and heading elements within singular posts, pahes and custom post types.
WAJ Links Developer Profile
4 plugins · 10 total installs
How We Detect WAJ Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/waj-links/HTML / DOM Fingerprints
[link [mail-link [post-link [category-link