WP Affiliate Link Manager Security & Risk Analysis

wordpress.org/plugins/affiliate-booster

WP Affiliate Link Manager add the links to your keywords based on the selection being made to make it easier to add the link to the keywords.

10 active installs v1.1 PHP + WP 4.0+ Updated Nov 25, 2024
affiliate-boosteraffiliate-link-manageraffiliate-marketinglink-manager
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Affiliate Link Manager Safe to Use in 2026?

Generally Safe

Score 92/100

WP Affiliate Link Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The Affiliate Booster plugin v1.1 exhibits several significant security concerns despite its clean vulnerability history. The static analysis reveals a considerable attack surface with two AJAX handlers, both of which lack authentication checks. This is a critical oversight, as it opens the door to potential unauthorized actions or data manipulation by unauthenticated users. Furthermore, the taint analysis identified one flow with an unsanitized path, indicating a potential for data to be processed without proper validation, which could lead to vulnerabilities like stored XSS or path traversal if the data originates from user input.

While the plugin demonstrates good practices in using prepared statements for a majority of its SQL queries and has no recorded CVEs, these strengths are overshadowed by the identified security weaknesses. The lack of nonce checks and capability checks on the AJAX endpoints, combined with a low percentage of properly escaped outputs (only 30%), points to a development approach that has not prioritized robust security measures. The absence of any known vulnerabilities in its history might suggest that these issues have not been actively exploited or discovered yet, but this should not lead to complacency.

In conclusion, Affiliate Booster v1.1 has a concerning security posture due to its unprotected AJAX endpoints and a high-severity taint flow. While the absence of CVEs is positive, the identified code-level risks, particularly the lack of authentication on entry points and insufficient output escaping, warrant immediate attention and remediation to prevent potential exploitation.

Key Concerns

  • AJAX handlers without auth checks
  • High severity taint flow with unsanitized paths
  • Low percentage of properly escaped outputs
  • No nonce checks on AJAX handlers
  • No capability checks on AJAX handlers
Vulnerabilities
None known

WP Affiliate Link Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP Affiliate Link Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
8
18 prepared
Unescaped Output
47
20 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

69% prepared26 total queries

Output Escaping

30% escaped67 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<affiliate-response> (affiliate-response.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

WP Affiliate Link Manager Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_afbt_db_functionaffiliate-classes.php:608
noprivwp_ajax_afbt_db_functionaffiliate-classes.php:609
WordPress Hooks 4
actionadmin_menuaffiliate-booster.php:56
filterthe_contentaffiliate-booster.php:61
actionwp_footeraffiliate-booster.php:62
actionadmin_enqueue_scriptsaffiliate-classes.php:603
Maintenance & Trust

WP Affiliate Link Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedNov 25, 2024
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP Affiliate Link Manager Developer Profile

Raj

4 plugins · 50 total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
638 days
View full developer profile
Detection Fingerprints

How We Detect WP Affiliate Link Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliate-booster/css/style.css/wp-content/plugins/affiliate-booster/js/affiliate-booster.js
Script Paths
/wp-content/plugins/affiliate-booster/js/affiliate-booster.js
Version Parameters
affiliate-booster/css/style.css?ver=affiliate-booster/js/affiliate-booster.js?ver=

HTML / DOM Fingerprints

CSS Classes
affiliate-booster
Data Attributes
data-column-iddata-identifierdata-formatterdata-sortabledata-row-iddata-toggle
JS Globals
affiliate_booster_ajax_urlaffiliate_booster_ajax_nonce
FAQ

Frequently Asked Questions about WP Affiliate Link Manager