
WP SoftLinks Security & Risk Analysis
wordpress.org/plugins/wp-softlinksThis plugin allows you to use a simple HTML tag that dynamically generates href and src tags. Easy to use, and extremely helpful.
Is WP SoftLinks Safe to Use in 2026?
Generally Safe
Score 85/100WP SoftLinks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-softlinks v1.0.1 plugin exhibits a seemingly strong security posture based on the provided static analysis, with no identified attack surface, dangerous functions, file operations, or external HTTP requests. The absence of recorded vulnerabilities and CVEs also suggests a history of responsible development or a lack of targeting. However, the static analysis reveals significant underlying risks.
Despite the zero attack surface reported, the plugin's sole SQL query is not using prepared statements, representing a critical SQL injection vulnerability. Furthermore, none of the identified output operations are properly escaped, posing a risk of cross-site scripting (XSS) attacks. The complete lack of nonce and capability checks, especially in conjunction with potential data inputs (though not explicitly identified as entry points), creates a broad opportunity for unauthorized actions if any future vulnerabilities or indirect entry points are discovered.
While the vulnerability history is clean, this does not negate the critical risks identified in the code analysis. The absence of prepared statements and output escaping are fundamental security flaws that should be addressed immediately. The plugin's strengths lie in its limited scope and lack of external dependencies or complex features, but these are overshadowed by the high-severity coding practices observed. A balanced conclusion is that the plugin has a good track record but contains severe, unaddressed coding vulnerabilities that present an immediate risk.
Key Concerns
- Raw SQL query without prepared statements
- Output not properly escaped
- Missing nonce checks
- Missing capability checks
WP SoftLinks Security Vulnerabilities
WP SoftLinks Release Timeline
WP SoftLinks Code Analysis
SQL Query Safety
Output Escaping
WP SoftLinks Attack Surface
WordPress Hooks 5
Maintenance & Trust
WP SoftLinks Maintenance & Trust
Maintenance Signals
Community Trust
WP SoftLinks Alternatives
Black Studio TinyMCE Widget
black-studio-tinymce-widget
The visual editor widget for WordPress.
AddQuicktag
addquicktag
This plugin makes it easy to add Quicktags to the html - and visual-editor.
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor
post-and-page-builder
Post and Page Builder is a standalone plugin which adds functionality to the existing TinyMCE Editor.
TinyMCE Templates
tinymce-templates
TinyMCE Template plugin will enable to use HTML template on WordPress Visual Editor.
Visual Term Description Editor
visual-term-description-editor
Replaces the plain-text category and tag description editor with a visual editor.
WP SoftLinks Developer Profile
1 plugin · 10 total installs
How We Detect WP SoftLinks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-softlinks/assets/css/softlinks_admin.css/wp-content/plugins/wp-softlinks/assets/js/wplink.min.js/wp-content/plugins/wp-softlinks/assets/js/wplink.min.jswp-softlinks/assets/css/softlinks_admin.css?ver=wp-softlinks/assets/js/wplink.min.js?ver=HTML / DOM Fingerprints
data-wp-idsoftlink_attribute