WP Linker / Internal linking creator Security & Risk Analysis

wordpress.org/plugins/wp-linker

Plugins adds dynamically links across your website according to your configured internal linking campaign.

10 active installs v1.2 PHP 7.0+ WP 5.0+ Updated Dec 15, 2022
internal-linkinglink-building-pluginseo-toolwp-linker
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Linker / Internal linking creator Safe to Use in 2026?

Generally Safe

Score 85/100

WP Linker / Internal linking creator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The wp-linker plugin v1.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries, exclusively using prepared statements, and has a high percentage of properly escaped output, minimizing risks of injection and XSS vulnerabilities. The absence of known vulnerabilities in its history is also a strong indicator of mature development and security awareness. However, the plugin presents significant security concerns due to its attack surface. With two AJAX handlers, neither of which implements authentication or capability checks, there is a substantial risk of unauthorized actions being performed. The lack of nonce checks further exacerbates this, making these AJAX endpoints vulnerable to CSRF attacks. The absence of taint analysis results and dangerous function signals is reassuring, but it doesn't mitigate the identified entry point vulnerabilities. Overall, while the plugin is strong in data handling and output sanitization, the unprotected AJAX endpoints are a critical weakness that requires immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX
  • No capability checks on AJAX
Vulnerabilities
None known

WP Linker / Internal linking creator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP Linker / Internal linking creator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
82 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

95% escaped86 total outputs
Attack Surface
2 unprotected

WP Linker / Internal linking creator Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_wp_linker_ajax_handlerclasses\AjaxHandler.php:9
authwp_ajax_wp_linker_ajax_handlerclasses\AjaxHandler.php:13
WordPress Hooks 3
actionadmin_menuclasses\Controller.php:14
filterthe_contentclasses\Controller.php:19
actionadmin_enqueue_scriptsincludes\functions.php:35
Maintenance & Trust

WP Linker / Internal linking creator Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 15, 2022
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP Linker / Internal linking creator Developer Profile

Mateusz Grzybowski

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Linker / Internal linking creator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-linker/assets/js/repeater-dist.js/wp-content/plugins/wp-linker/assets/js/select2.min.js/wp-content/plugins/wp-linker/assets/js/admin_scripts-dist.js/wp-content/plugins/wp-linker/assets/css/admin_styles.css/wp-content/plugins/wp-linker/assets/js/tooltip-dist.js/wp-content/plugins/wp-linker/assets/js/scripts-dist.js/wp-content/plugins/wp-linker/assets/css/styles.css
Script Paths
/wp-content/plugins/wp-linker/assets/js/repeater-dist.js/wp-content/plugins/wp-linker/assets/js/select2.min.js/wp-content/plugins/wp-linker/assets/js/admin_scripts-dist.js/wp-content/plugins/wp-linker/assets/js/tooltip-dist.js/wp-content/plugins/wp-linker/assets/js/scripts-dist.js
Version Parameters
wp-linker/assets/js/repeater-dist.js?ver=wp-linker/assets/js/select2.min.js?ver=wp-linker/assets/js/admin_scripts-dist.js?ver=wp-linker/assets/css/admin_styles.css?ver=wp-linker/assets/js/tooltip-dist.js?ver=wp-linker/assets/js/scripts-dist.js?ver=wp-linker/assets/css/styles.css?ver=

HTML / DOM Fingerprints

JS Globals
wp_linker_ajax
FAQ

Frequently Asked Questions about WP Linker / Internal linking creator