Affiliate Link Marker Security & Risk Analysis

wordpress.org/plugins/affiliate-link-marker

Mark your Affiliate Links with a *, add rel="nofollow sponsored noopener" to affiliate links and attach a disclosure at the end of e …

400 active installs v1.0.9 PHP 7.0+ WP 4.6+ Updated Dec 5, 2025
affiliatelinksmultisitenofollowsponsored
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Affiliate Link Marker Safe to Use in 2026?

Generally Safe

Score 100/100

Affiliate Link Marker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The plugin 'affiliate-link-marker' v1.0.9 exhibits a generally strong security posture based on the provided static analysis. The absence of identified dangerous functions, SQL queries executed with prepared statements, file operations, and external HTTP requests are all positive indicators. Furthermore, the lack of known CVEs and a clean vulnerability history suggest a history of secure development. However, there are areas for improvement. The analysis indicates a low number of output escaping mechanisms, with a significant portion (33%) not properly escaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected directly into the output. Additionally, the absence of capability checks on any entry points is a concern, as it implies that any authenticated user, regardless of their role, could potentially trigger plugin functionality.

Key Concerns

  • Unescaped output detected
  • No capability checks on entry points
Vulnerabilities
None known

Affiliate Link Marker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Affiliate Link Marker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped3 total outputs
Attack Surface

Affiliate Link Marker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionnetwork_admin_menuadmin\settings-page-network.php:12
actionadmin_initadmin\settings-page-network.php:13
actionnetwork_admin_edit_affiliate_marker_settingsadmin\settings-page-network.php:28
actionadmin_menuadmin\settings-page.php:12
actionadmin_initadmin\settings-page.php:13
filterthe_contentaffiliate-marker.php:113
filterterm_descriptionaffiliate-marker.php:114
filtercomment_textaffiliate-marker.php:115
filterwp_targeted_link_relaffiliate-marker.php:116
filterthe_contentaffiliate-marker.php:125
actionwp_headaffiliate-marker.php:130
actioninitaffiliate-marker.php:154
Maintenance & Trust

Affiliate Link Marker Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 5, 2025
PHP min version7.0
Downloads6K

Community Trust

Rating100/100
Number of ratings6
Active installs400
Developer Profile

Affiliate Link Marker Developer Profile

Johannes Kinast

2 plugins · 20K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Affiliate Link Marker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
affiliate-marker-disclosure
Data Attributes
rel*=sponsored
FAQ

Frequently Asked Questions about Affiliate Link Marker