Easy External Links Security & Risk Analysis

wordpress.org/plugins/wp-links

Take control of external links in WordPress posts, pages & comments. Insert rel=external nofollow and target=_blank to all your external links.

300 active installs v2.2.3 PHP + WP 3.0+ Updated Feb 25, 2016
externallinksnew-tabnew-windowseo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy External Links Safe to Use in 2026?

Generally Safe

Score 85/100

Easy External Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'wp-links' plugin v2.2.3 exhibits a generally positive security posture based on the provided static analysis. The absence of identified dangerous functions, raw SQL queries, file operations, external HTTP requests, and a zero-count for known CVEs are all strong indicators of a well-developed and secure plugin. The zero attack surface also suggests that the plugin does not expose any direct entry points for potential attackers, which is a significant security advantage.

However, there are notable areas of concern. The extremely low percentage of properly escaped output (1%) is a critical weakness. This means that nearly all dynamic data outputted by the plugin is susceptible to cross-site scripting (XSS) attacks. The complete lack of nonce checks and capability checks, coupled with zero identified entry points, suggests that while the plugin may not have direct attack vectors, any functionality that *does* exist is not protected against unauthorized execution or manipulation, making it reliant on the overall WordPress security context.

In conclusion, while the plugin's lack of known vulnerabilities and attack surface are commendable, the severe lack of output escaping represents a significant and easily exploitable security risk. The absence of nonce and capability checks further exacerbates this, as it allows for potentially malicious actions to be performed without proper authorization. The plugin's strengths lie in its minimal exposure and reliance on prepared statements, but the output escaping issue is a critical flaw that needs immediate attention.

Key Concerns

  • Extremely low output escaping percentage
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Easy External Links Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Easy External Links Release Timeline

v1.9.5
v1.9.3
v1.9.2
v1.9.1
v1.9
v1.8
v1.7
v1.6
v1.5
v1.4
v1.3
v1.1
Code Analysis
Analyzed Mar 16, 2026

Easy External Links Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
101
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

1% escaped102 total outputs
Attack Surface

Easy External Links Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterthe_contentwp-links.php:54
filterthe_excerptwp-links.php:55
filtercomment_textwp-links.php:56
actionwp_headwp-links.php:58
actionadmin_menuwp-links.php:65
actionadmin_initwp-links.php:69
actionwp_headwp-links.php:117
Maintenance & Trust

Easy External Links Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedFeb 25, 2016
PHP min version
Downloads28K

Community Trust

Rating100/100
Number of ratings16
Active installs300
Developer Profile

Easy External Links Developer Profile

Jorge A. Gonzalez

1 plugin · 300 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy External Links

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-links/icons/

HTML / DOM Fingerprints

CSS Classes
wp-links-icon
HTML Comments
<!-- WP Links CSS-->
Data Attributes
wp-links-icon
FAQ

Frequently Asked Questions about Easy External Links