AffiEasy Security & Risk Analysis

wordpress.org/plugins/affieasy

Create reusable affiliate links and responsive comparison tables from a single WordPress admin interface.

30 active installs v1.2.2 PHP 7.2+ WP 5.1+ Updated Mar 12, 2026
affiliate-linkscomparison-tablespricing-tablesresponsivetables
99
A · Safe
CVEs total2
Unpatched0
Last CVEMay 29, 2024
Download
Safety Verdict

Is AffiEasy Safe to Use in 2026?

Generally Safe

Score 99/100

AffiEasy has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: May 29, 2024Updated 21d ago
Risk Assessment

The Affieasy plugin version 1.2.2 exhibits a generally good security posture, with a notable absence of critical vulnerabilities in static analysis and taint flows. The plugin demonstrates strong adherence to secure coding practices by utilizing prepared statements for the vast majority of its SQL queries and implementing nonce and capability checks on its entry points. The lack of dangerous functions, file operations, and external HTTP requests further strengthens its defensive capabilities. However, a significant weakness lies in its output escaping, where only 63% of outputs are properly escaped, leaving a substantial portion potentially vulnerable to Cross-Site Scripting (XSS) attacks. The historical vulnerability data, specifically two medium-severity CVEs, both attributed to Cross-Site Request Forgery (CSRF), suggests a pattern of past security oversights in input validation or handling user actions. While there are currently no unpatched vulnerabilities, the recurring nature of CSRF indicates a need for ongoing vigilance and potentially more robust CSRF protection mechanisms. Overall, Affieasy has a solid foundation in secure development but requires attention to output escaping and a review of its historical CSRF vulnerabilities to achieve a truly robust security profile.

Key Concerns

  • Moderate output escaping coverage
  • Past medium severity CSRF vulnerabilities
Vulnerabilities
2

AffiEasy Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-4218medium · 6.5Cross-Site Request Forgery (CSRF)

AffiEasy <= 1.1.6 - Cross-Site Request Forgery to Various Actions

May 29, 2024 Patched in 1.1.7 (8d)
CVE-2024-32435medium · 4.3Cross-Site Request Forgery (CSRF)

AffiEasy <= 1.1.4 - Cross-Site Request Forgery

Apr 12, 2024 Patched in 1.1.6 (6d)
Code Analysis
Analyzed Mar 16, 2026

AffiEasy Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
20 prepared
Unescaped Output
89
153 escaped
Nonce Checks
9
Capability Checks
7
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

87% prepared23 total queries

Output Escaping

63% escaped242 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<afes-link-search-message> (inc\afes-link-search-message.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AffiEasy Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_afes_detect_webshopclasses\class-afes-affiliation-table-admin.php:31
authwp_ajax_afes_quick_create_linkclasses\class-afes-affiliation-table-admin.php:32
WordPress Hooks 7
actionadmin_initaffieasy.php:35
actionplugins_loadedaffieasy.php:72
actionadmin_menuclasses\class-afes-affiliation-table-admin.php:21
actiontemplate_redirectclasses\class-afes-affiliation-table-admin.php:26
actionadd_meta_boxesclasses\class-afes-affiliation-table-admin.php:28
actionadmin_enqueue_scriptsclasses\class-afes-affiliation-table-admin.php:29
actionwp_enqueue_scriptsclasses\class-afes-affiliation-table-admin.php:34
Maintenance & Trust

AffiEasy Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 12, 2026
PHP min version7.2
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

AffiEasy Developer Profile

perrinalexandre05

1 plugin · 30 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect AffiEasy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affieasy/css/rendering.css
Version Parameters
affieasy/css/rendering.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-webshop-iddata-table-iddata-product-id
Shortcode Output
[affieasy_table[affieasy_link
FAQ

Frequently Asked Questions about AffiEasy