WP LinkPress Lite – LinkedIn comments for WordPress Security & Risk Analysis

wordpress.org/plugins/wp-linkpress-lite

Place comments with a LinkedIn profile on a WordPress website, and share the comment & website URL on the LinkedIn activity feed.

20 active installs v1.1 PHP 7.1+ WP 5.1+ Updated Dec 17, 2022
commentslinkedinsocial
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP LinkPress Lite – LinkedIn comments for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

WP LinkPress Lite – LinkedIn comments for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The wp-linkpress-lite v1.1 plugin exhibits a concerning security posture due to a large number of unprotected AJAX handlers. While the static analysis did not identify any critical or high-severity vulnerabilities, the presence of 8 AJAX handlers without any authentication checks presents a significant attack surface. This means an unauthenticated attacker could potentially trigger these functionalities, leading to unintended behavior or information disclosure. The taint analysis also highlighted two flows with unsanitized paths, which, although not classified as critical or high, warrants attention as they could be points of weakness if exploited in conjunction with other issues.

Despite the absence of a known vulnerability history, this should not be interpreted as a guarantee of complete security. The plugin's lack of proper authorization on a majority of its entry points is a fundamental security flaw. The presence of raw SQL queries without prepared statements also adds to the potential risk of SQL injection, though its severity is not immediately apparent without further context. The plugin does demonstrate some good practices, such as a moderate level of output escaping and proper nonce checks on some actions. However, the unprotected AJAX handlers are the most pressing concern and significantly elevate the overall risk.

Key Concerns

  • AJAX handlers without auth checks
  • SQL queries without prepared statements
  • Unsanitized paths in taint analysis
  • Moderate output escaping
Vulnerabilities
None known

WP LinkPress Lite – LinkedIn comments for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP LinkPress Lite – LinkedIn comments for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
20
22 escaped
Nonce Checks
1
Capability Checks
2
File Operations
3
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

52% escaped42 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
post_new_comment (includes\class-wplinkpress-lite-frontend.php:30)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
8 unprotected

WP LinkPress Lite – LinkedIn comments for WordPress Attack Surface

Entry Points9
Unprotected8

AJAX Handlers 8

authwp_ajax_add_comment_sessionincludes\class-wplinkpress-lite-core.php:30
noprivwp_ajax_add_comment_sessionincludes\class-wplinkpress-lite-core.php:31
authwp_ajax_authorize_linkedin_oauthincludes\class-wplinkpress-lite-core.php:32
noprivwp_ajax_authorize_linkedin_oauthincludes\class-wplinkpress-lite-core.php:33
authwp_ajax_post_commentincludes\class-wplinkpress-lite-frontend.php:13
noprivwp_ajax_post_commentincludes\class-wplinkpress-lite-frontend.php:14
authwp_ajax_wplinkpress_logoutincludes\class-wplinkpress-lite-frontend.php:15
noprivwp_ajax_wplinkpress_logoutincludes\class-wplinkpress-lite-frontend.php:16

Shortcodes 1

[wplinkpress_comments] includes\class-wplinkpress-lite-frontend.php:11
WordPress Hooks 16
actionadd_meta_boxesadmin\wplinkpress-lite-admin-actions.php:18
actionwplinkpress_settings_tabadmin\wplinkpress-lite-admin-actions.php:19
actionwplinkpress_settings_tab_contentadmin\wplinkpress-lite-admin-actions.php:20
filterparse_queryadmin\wplinkpress-lite-admin-actions.php:21
actionsave_postadmin\wplinkpress-lite-admin-actions.php:22
actionadmin_menuadmin\wplinkpress-lite-admin-settings.php:17
actionadmin_initadmin\wplinkpress-lite-admin-settings.php:18
actionadmin_enqueue_scriptsadmin\wplinkpress-lite-admin-settings.php:19
actionadmin_initincludes\class-wplinkpress-lite-core.php:17
actionwp_enqueue_scriptsincludes\class-wplinkpress-lite-core.php:29
actionadmin_initincludes\class-wplinkpress-lite-core.php:35
actioninitincludes\class-wplinkpress-lite-frontend.php:9
filterthe_contentincludes\class-wplinkpress-lite-frontend.php:10
actionend_comment_sessionincludes\class-wplinkpress-lite-frontend.php:12
actionplugins_loadedwplinkpress-lite.php:28
actionadmin_noticeswplinkpress-lite.php:135
Maintenance & Trust

WP LinkPress Lite – LinkedIn comments for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 17, 2022
PHP min version7.1
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

WP LinkPress Lite – LinkedIn comments for WordPress Developer Profile

Lucy Eind

3 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP LinkPress Lite – LinkedIn comments for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-linkpress-lite/admin/assets/css/wplinkpress-lite-admin.css/wp-content/plugins/wp-linkpress-lite/assets/media/non-user-icon.jpg
Script Paths
/wp-content/plugins/wp-linkpress-lite/admin/assets/js/wplinkpress-lite-admin.js
Version Parameters
wp-linkpress-lite/admin/assets/css/wplinkpress-lite-admin.css?ver=wp-linkpress-lite/admin/assets/js/wplinkpress-lite-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-linkpress-lite-admin-notice
HTML Comments
<!-- WP LinkPress Lite database update is required, please click button to proceed --><!-- WP LinkPress Lite plugin has been updated! -->
Data Attributes
data-wplinkpress-ajaxurl
JS Globals
wplinkpress
FAQ

Frequently Asked Questions about WP LinkPress Lite – LinkedIn comments for WordPress