
WP Dynamic Links Security & Risk Analysis
wordpress.org/plugins/wp-dynamic-linksWP Dynamic Links makes it simple to shorten your URLs, track your links, split test, and geo-target.
Is WP Dynamic Links Safe to Use in 2026?
Use With Caution
Score 63/100WP Dynamic Links has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "wp-dynamic-links" plugin v1.0.1 exhibits a mixed security posture. While it boasts a zero attack surface in terms of directly exposed entry points like AJAX, REST API, shortcodes, and cron events, this is somewhat misleading given the identified code signals. The presence of dangerous functions like `create_function` and `unserialize` raises immediate concerns about potential code execution vulnerabilities if these functions are invoked with untrusted input. Furthermore, the fact that only 50% of output is properly escaped suggests a significant risk of Cross-Site Scripting (XSS) vulnerabilities, especially in conjunction with the taint analysis revealing two flows with unsanitized paths. The plugin's vulnerability history, marked by a medium severity CVE for XSS that is currently unpatched and discovered in the future, strongly indicates a pattern of insecure coding practices regarding input sanitization and output encoding. This unpatched vulnerability is a critical immediate risk. While the use of prepared statements for SQL queries is a positive indicator, it doesn't outweigh the clear and present dangers highlighted by the dangerous functions, poor output escaping, and the unpatched XSS vulnerability. The plugin should not be considered secure in its current state.
Key Concerns
- Unpatched CVE (Medium severity, XSS)
- Dangerous functions: create_function, unserialize
- Low output escaping percentage (50%)
- Taint flows with unsanitized paths (2)
- File operations present
WP Dynamic Links Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Dynamic Links <= 1.0.1 - Reflected Cross-Site Scripting
WP Dynamic Links Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Dynamic Links Attack Surface
WordPress Hooks 6
Maintenance & Trust
WP Dynamic Links Maintenance & Trust
Maintenance Signals
Community Trust
WP Dynamic Links Alternatives
Affiliate Links – Link Cloaking and Management
affiliate-links
Create any redirect links to any website from your WordPress Admin. Perfect for the affiliate links masking.
My Affiliate Link
my-affiliate-link
A plugin that creates shortcodes for use with any affiliate cloaking service or plugin. Formats affiliate links so they aren't indexed by the sea …
Premium Link Cloaker Lite
premium-link-cloaker-lite
Awesome yet easy-to-use link cloaker, designed for affiliate marketers. 100% newbie friendly.
WP affiliate link
wp-affiliate-link
this plugin will hide your affiliate link.
WP Link Manager
wp-link-manager
Wordpress plugin to create pretty and short link based on your site URL for external (or internal) ugly links
WP Dynamic Links Developer Profile
4 plugins · 124K total installs
How We Detect WP Dynamic Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-dynamic-links/assets/css/style.css/wp-content/plugins/wp-dynamic-links/assets/js/script.js/wp-content/plugins/wp-dynamic-links/assets/js/script.jswp-dynamic-links/assets/css/style.css?ver=wp-dynamic-links/assets/js/script.js?ver=HTML / DOM Fingerprints
PMLC_ROOT_URL