WP Easy Directory Link Security & Risk Analysis

wordpress.org/plugins/wp-easy-directory-link

A simple and easy use plugin that allows to create a directory link page. Make software tools lists, digital resources or business address, all organi …

10 active installs v1.3 PHP + WP 3.3+ Updated Jun 20, 2015
directoryeasylinkslistingsimple
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Easy Directory Link Safe to Use in 2026?

Generally Safe

Score 85/100

WP Easy Directory Link has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'wp-easy-directory-link' plugin v1.3 presents a generally positive security posture, adhering to several good development practices. The absence of any known vulnerabilities or CVEs in its history is a strong indicator of a well-maintained and secure codebase. Furthermore, the plugin demonstrates responsible SQL handling by exclusively using prepared statements, mitigating the risk of SQL injection attacks. The limited attack surface, with only one shortcode and no unprotected entry points, also contributes to its security. However, a significant concern arises from the low percentage of properly escaped output (20%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient care within the plugin's output mechanisms. The lack of nonce checks and capability checks on its single entry point, while not a critical issue given the limited attack surface, could be improved for enhanced security, especially if the plugin's functionality were to expand in the future. Overall, while the plugin is currently secure due to its simple nature and lack of historical issues, the unescaped output represents a notable weakness that requires attention to prevent potential XSS exploits.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

WP Easy Directory Link Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Easy Directory Link Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

WP Easy Directory Link Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped5 total outputs
Attack Surface

WP Easy Directory Link Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wp_edl_init] wp-easy-directory-link_functions.php:107
WordPress Hooks 3
filterpre_option_link_manager_enabledwp-easy-directory-link.php:28
actionplugins_loadedwp-easy-directory-link.php:31
actioninitwp-easy-directory-link.php:34
Maintenance & Trust

WP Easy Directory Link Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedJun 20, 2015
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

WP Easy Directory Link Developer Profile

barrahome

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Easy Directory Link

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-easy-directory-link/wp-easy-directory-link_functions.php

HTML / DOM Fingerprints

CSS Classes
linkBoxbookmark_categories
Shortcode Output
<form role="search" method="post" id="searchform" class="searchform" action="<input type="text" value="" name="query" id="query"><input type="submit" id="searchsubmit" value="<div class="linkBox">
FAQ

Frequently Asked Questions about WP Easy Directory Link