
WP Links Page Security & Risk Analysis
wordpress.org/plugins/wp-links-pageThis plugin allows you to create a dynamic link gallery with screenshots of each link.
Is WP Links Page Safe to Use in 2026?
Generally Safe
Score 95/100WP Links Page has a strong security track record. Known vulnerabilities have been patched promptly.
The 'wp-links-page' v5.0 plugin exhibits a strong security posture in its current static analysis, with no direct critical or high-severity code vulnerabilities identified. All SQL queries are properly prepared, and output is consistently escaped, indicating good development practices for preventing common web attacks like SQL injection and cross-site scripting. The plugin also implements nonce and capability checks on its entry points, further enhancing its security by restricting unauthorized access and actions. The limited attack surface, with no unprotected AJAX handlers or REST API routes, is also a positive sign.
However, the plugin's historical vulnerability data is a significant concern. Having accumulated five medium-severity vulnerabilities in the past, including SQL injection, missing authorization, CSRF, and XSS, suggests a pattern of past security weaknesses. While these issues are reportedly patched, the frequency and variety of past vulnerabilities indicate potential underlying coding practices that might still be present or could re-emerge in future updates if not rigorously addressed. The fact that the last vulnerability was very recent (2025-10-10) also warrants attention, suggesting ongoing security challenges.
In conclusion, 'wp-links-page' v5.0 demonstrates commendable adherence to secure coding principles in its current version. The absence of immediate threats from static analysis is reassuring. Nevertheless, the plugin's past security track record, characterized by multiple medium-severity vulnerabilities of various types, necessitates a cautious approach. Users should remain vigilant for future updates and be aware of the plugin's history of security issues.
Key Concerns
- 5 past medium vulnerabilities
WP Links Page Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
WP Links Page <= 4.9.6 - Authenticated (Subscriber+) SQL Injection
WP Links Page <= 4.9.6 - Authenticated (Subscriber+) SQL Injection
WP Links Page <= 4.9.5 - Missing Authorization to Authenticated (Subscriber+) Limited Image Update
WP Links Page <= 4.9.4 - Cross-Site Request Forgery via wplf_ajax_update_screenshots
WP Links Page <= 4.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
WP Links Page Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Links Page Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 25
Scheduled Events 4
Maintenance & Trust
WP Links Page Maintenance & Trust
Maintenance Signals
Community Trust
WP Links Page Alternatives
Simple Link Directory
simple-link-directory
Free LINK DIRECTORY Plugin for WordPress to Curate Links for Web Directory. Link management, Directory Listings, Link Archive, Vendor Directory
Open Links Directory
odlinks
Build A Webpage directory The plugin will help you to build a website directory and allow the site visitors to submit links by themselves.
WP Links Page Developer Profile
3 plugins · 6K total installs
How We Detect WP Links Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-links-page/css/wplp-style.css/wp-content/plugins/wp-links-page/js/wplp-script.js/wp-content/plugins/wp-links-page/images/loading.gif/wp-content/plugins/wp-links-page/js/wplp-script.jswp-links-page/css/wplp-style.css?ver=wp-links-page/js/wplp-script.js?ver=HTML / DOM Fingerprints
ssdata-wplp_iddata-wplp_link_idwplpf_admin_paramswplf_media_params[wp_links_page]