
LCT Text/Image Linking Shortcode Security & Risk Analysis
wordpress.org/plugins/wp-textimage-linking-shortcodeUse linking short codes to save you time and eliminate stress when restructuring your site pages & post.
Is LCT Text/Image Linking Shortcode Safe to Use in 2026?
Generally Safe
Score 85/100LCT Text/Image Linking Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "wp-textimage-linking-shortcode" v4.2.2 reveals a generally positive security posture with no identified attack surface, dangerous functions, file operations, external requests, or taint flows. The absence of known vulnerabilities in its history further strengthens this impression. However, there are some areas for improvement. The plugin has a single SQL query that is not using prepared statements, which poses a moderate risk of SQL injection if user-supplied data is used directly in this query. Additionally, while most output is properly escaped, a minority of outputs are not, potentially leading to cross-site scripting (XSS) vulnerabilities. The complete lack of nonce and capability checks across all potential entry points (even though the identified entry points are zero) is a significant concern, as it implies no authorization or CSRF protection is implemented by the plugin itself. Overall, the plugin demonstrates good practices in avoiding common pitfalls like dangerous functions and external requests, but the unpatched SQL and output escaping issues, coupled with the complete absence of any authorization checks, present potential security weaknesses that require attention.
Key Concerns
- Raw SQL without prepared statements
- Unescaped output (21% of outputs)
- Missing nonce checks
- Missing capability checks
LCT Text/Image Linking Shortcode Security Vulnerabilities
LCT Text/Image Linking Shortcode Code Analysis
SQL Query Safety
Output Escaping
LCT Text/Image Linking Shortcode Attack Surface
WordPress Hooks 3
Maintenance & Trust
LCT Text/Image Linking Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
LCT Text/Image Linking Shortcode Alternatives
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Internal Link Juicer: SEO Auto Linker for WordPress
internal-links
Improve your SEO and your user experience through internal linkbuilding. Automated links between your posts based on a smart keyword configuration.
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
LCT Text/Image Linking Shortcode Developer Profile
4 plugins · 120 total installs
How We Detect LCT Text/Image Linking Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-textimage-linking-shortcode/css/wptisc-admin.css/wp-content/plugins/wp-textimage-linking-shortcode/js/wptisc-admin.js/wp-content/plugins/wp-textimage-linking-shortcode/js/wptisc-admin.jswp-textimage-linking-shortcode/css/wptisc-admin.css?ver=wp-textimage-linking-shortcode/js/wptisc-admin.js?ver=HTML / DOM Fingerprints
wptisc_helpwptisc_readmewptisc_search_boxlive_search_resultsactiveid="wptisc_meta_box"id="wptisc_post_title"class="wptisc_help"class="wptisc_readme"class="wptisc_search_box"class="live_search_results"+2 morewptisc_show_shortcode/wp-json/wp-textimage-linking-shortcode/v1<a href="id='text=''><img src="