No Sweat WP Internal Links Lite Security & Risk Analysis

wordpress.org/plugins/wp-internal-links-lite

No Sweat WP Internal Links Lite allows you to create silos, powerful internal linking structures that improve your on-site SEO.

20 active installs v2.4.3 PHP + WP 3.2+ Updated Sep 10, 2015
autolinksautomatic-linksinternal-linksno-sweat-wp-internal-linkswp-internal-links
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is No Sweat WP Internal Links Lite Safe to Use in 2026?

Generally Safe

Score 85/100

No Sweat WP Internal Links Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The wp-internal-links-lite plugin version 2.4.3 exhibits a concerning security posture, primarily due to its unprotected entry points and unsanitized data flows. While the plugin avoids known CVEs and dangerous functions, the static analysis reveals significant weaknesses. The presence of two AJAX handlers without any authentication checks creates a substantial attack surface, allowing potentially any user, including unauthenticated ones, to interact with these functions. Furthermore, the taint analysis highlights three critical severity flows with unsanitized paths, indicating that user-supplied data could be used in a dangerous way within the application without proper validation or sanitization, posing a risk of injection attacks or other vulnerabilities. The plugin's lack of nonce checks and capability checks on its entry points exacerbates these risks, as it fails to implement standard WordPress security measures to protect against common web exploits. The high percentage of improperly escaped output further compounds these issues, potentially leading to Cross-Site Scripting (XSS) vulnerabilities. Despite the absence of documented CVEs, the identified code-level weaknesses suggest a high potential for exploitation. Developers should prioritize addressing the unprotected AJAX handlers, unsanitized taint flows, and output escaping issues.

Key Concerns

  • AJAX handlers without authentication checks
  • Critical severity taint flows (unsanitized)
  • Critical severity taint flows (unsanitized)
  • Critical severity taint flows (unsanitized)
  • No nonce checks on entry points
  • No capability checks on entry points
  • Low output escaping (2% proper)
Vulnerabilities
None known

No Sweat WP Internal Links Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

No Sweat WP Internal Links Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
16 prepared
Unescaped Output
94
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

SQL Query Safety

80% prepared20 total queries

Output Escaping

2% escaped96 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
inlpln_dismiss (inter-links.php:334)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

No Sweat WP Internal Links Lite Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_get_structureinter-links.php:102
authwp_ajax_inlpln_dismissinter-links.php:239
WordPress Hooks 5
actionadmin_menuinter-links.php:19
actioninitinter-links.php:20
actionadmin_enqueue_scriptsinter-links.php:40
filterthe_contentinter-links.php:64
actionadmin_noticesinter-links.php:238
Maintenance & Trust

No Sweat WP Internal Links Lite Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedSep 10, 2015
PHP min version
Downloads12K

Community Trust

Rating60/100
Number of ratings6
Active installs20
Developer Profile

No Sweat WP Internal Links Lite Developer Profile

Mikel Perez

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect No Sweat WP Internal Links Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-internal-links-lite/js/jquery.blockUI.js

HTML / DOM Fingerprints

CSS Classes
interlinks
FAQ

Frequently Asked Questions about No Sweat WP Internal Links Lite