Add & Replace Affiliate Links for Amazon Security & Risk Analysis

wordpress.org/plugins/add-replace-affiliate-links-for-amazon

Add & Replace Affiliate Links for Amazon plugin helps you to add or update Amazon Associate tag parameters in links.

600 active installs v1.0.6 PHP 7.0+ WP 5.6+ Updated Feb 10, 2022
amazonamazon-affiliateamazon-associateamazon-associates
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEJun 27, 2025
Download
Safety Verdict

Is Add & Replace Affiliate Links for Amazon Safe to Use in 2026?

Use With Caution

Score 63/100

Add & Replace Affiliate Links for Amazon has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jun 27, 2025Updated 4yr ago
Risk Assessment

The 'add-replace-affiliate-links-for-amazon' plugin v1.0.6 exhibits a mixed security posture. On the positive side, the static analysis shows a lack of critical code signals like dangerous functions or unsanitized taint flows, and all identified entry points (AJAX handlers) appear to have nonce and capability checks, indicating a good effort to protect against common web attacks. The plugin also avoids using file operations and has minimal external HTTP requests.

However, several areas raise concern. The low percentage of properly escaped output (30%) suggests a potential for cross-site scripting (XSS) vulnerabilities, especially given the plugin's history of XSS-related vulnerabilities. Furthermore, a significant portion of SQL queries (42%) are not using prepared statements, which can lead to SQL injection vulnerabilities if not handled with extreme care. The single known unpatched medium severity vulnerability is a notable risk that requires immediate attention.

While the plugin has a generally controlled attack surface and implements some crucial security checks, the presence of unpatched vulnerabilities and a high rate of unescaped output and raw SQL queries indicate areas that could be exploited. Addressing these specific weaknesses is paramount to improving the overall security of the plugin.

Key Concerns

  • Unpatched CVE (Medium Severity)
  • SQL queries not using prepared statements
  • Low percentage of properly escaped output
Vulnerabilities
1 published

Add & Replace Affiliate Links for Amazon Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-53285medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Add &amp; Replace Affiliate Links for Amazon <= 1.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jun 27, 2025Unpatched
Version History

Add & Replace Affiliate Links for Amazon Release Timeline

v1.0.6Current1 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.21 CVE
v1.0.11 CVE
Code Analysis
Analyzed Mar 16, 2026

Add & Replace Affiliate Links for Amazon Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
7 prepared
Unescaped Output
19
8 escaped
Nonce Checks
7
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

58% prepared12 total queries

Output Escaping

30% escaped27 total outputs
Attack Surface

Add & Replace Affiliate Links for Amazon Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 7

authwp_ajax_uralp_updateupd-amazon-plugin.php:62
authwp_ajax_uralp_backupupd-amazon-plugin.php:84
authwp_ajax_uralp_restoreupd-amazon-plugin.php:91
authwp_ajax_uralp_no_followupd-amazon-plugin.php:98
authwp_ajax_uralp_no_affiliateupd-amazon-plugin.php:110
authwp_ajax_uralp_expandupd-amazon-plugin.php:123
authwp_ajax_uralp_get_progressupd-amazon-plugin.php:135
WordPress Hooks 7
actionadmin_menuupd-amazon-plugin.php:36
actionuralp_hookupd-amazon-plugin.php:49
actionpost_updatedupd-amazon.php:207
actionpost_updatedupd-amazon.php:239
actionpost_updatedupd-amazon.php:372
actionpost_updatedupd-amazon.php:421
actionpost_updatedupd-amazon.php:470

Scheduled Events 1

uralp_hook
Maintenance & Trust

Add & Replace Affiliate Links for Amazon Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedFeb 10, 2022
PHP min version7.0
Downloads12K

Community Trust

Rating64/100
Number of ratings17
Active installs600
Developer Profile

Add & Replace Affiliate Links for Amazon Developer Profile

The Website Flip

1 plugin · 600 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Add & Replace Affiliate Links for Amazon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-replace-affiliate-links-for-amazon/assets/css/style.css/wp-content/plugins/add-replace-affiliate-links-for-amazon/assets/js/main.js/wp-content/plugins/add-replace-affiliate-links-for-amazon/assets/js/jquery.min.js
Script Paths
/wp-content/plugins/add-replace-affiliate-links-for-amazon/assets/js/main.js/wp-content/plugins/add-replace-affiliate-links-for-amazon/assets/js/jquery.min.js
Version Parameters
add-replace-affiliate-links-for-amazon/assets/css/style.css?ver=add-replace-affiliate-links-for-amazon/assets/js/main.js?ver=add-replace-affiliate-links-for-amazon/assets/js/jquery.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
upd_content_wrapperupd_content_cellupd_content_areameterprogress-bar
Data Attributes
id="progress-row"id="response-msg-row"id="response-msg"id="upd-amazon-plugin-form"id="new-id"
JS Globals
var ajax_url = '
FAQ

Frequently Asked Questions about Add & Replace Affiliate Links for Amazon