
Affiliate Links – Link Cloaking and Management Security & Risk Analysis
wordpress.org/plugins/affiliate-linksCreate any redirect links to any website from your WordPress Admin. Perfect for the affiliate links masking.
Is Affiliate Links – Link Cloaking and Management Safe to Use in 2026?
Generally Safe
Score 96/100Affiliate Links – Link Cloaking and Management has a strong security track record. Known vulnerabilities have been patched promptly.
The 'affiliate-links' plugin version 3.2.0 exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices, with 100% of outputs properly escaped and a significant portion of SQL queries utilizing prepared statements. The presence of nonce and capability checks across its entry points is also commendable. However, the taint analysis highlights a concerning "High" severity flow with unsanitized user input, indicating a potential for injection vulnerabilities. Furthermore, the plugin's vulnerability history, with 3 previously discovered CVEs including one high and two medium severity issues, suggests a pattern of past security weaknesses, even though there are currently no unpatched vulnerabilities. The plugin also has a history of vulnerabilities related to missing authorization and cross-site scripting, which require careful consideration.
While the current version appears to have addressed its past vulnerabilities and demonstrates good basic security hygiene, the identified high-severity taint flow is a significant red flag that demands immediate attention. The past vulnerability history, though seemingly resolved in this version, warrants vigilance. The plugin's strengths lie in its output escaping and use of prepared statements, but its weaknesses are exposed by the taint analysis and historical CVEs. Overall, it's a plugin that has improved but still carries a residual risk due to past issues and identified coding flaws.
Key Concerns
- High severity taint flow found
- 3 previously disclosed CVEs
- 1 High severity CVE in history
- 2 Medium severity CVEs in history
- 3 flows with unsanitized paths
Affiliate Links – Link Cloaking and Management Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Affiliate Links Lite <= 3.1.0 - Reflected Cross-Site Scripting
Affiliate Links: WordPress Plugin for Link Cloaking and Link Management <= 3.0.1 - Missing Authorization to Unauthenticated Import/Export and PHP Object Injection
Affiliate Links Lite <= 2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Affiliate Links – Link Cloaking and Management Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Affiliate Links – Link Cloaking and Management Attack Surface
AJAX Handlers 1
Shortcodes 3
WordPress Hooks 50
Maintenance & Trust
Affiliate Links – Link Cloaking and Management Maintenance & Trust
Maintenance Signals
Community Trust
Affiliate Links – Link Cloaking and Management Alternatives
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
simple-urls
Simple URLs helps you to manage links, create product displays, and grow your affiliate marketing business.
BetterLinks – URL Shortener, Link Tracking, Analytics & Affiliate Link Manager
betterlinks
Ultimate plugin to create, shorten, track and manage any URL. Gather analytics reports and run successful marketing campaigns easily.
URL Shortify – Simple and Easy URL Shortener
url-shortify
URL Shortify helps you beautify, manage, share & cloak any links on or off your WordPress website. Create links using your domain name!
Easy Affiliate Links
easy-affiliate-links
Easily manage and cloak all your affiliate links.
Email JavaScript Cloak
email-javascript-cloaker
A simple plugin to use JavaScript to cloak email addresses in your WordPress content (posts & pages).
Affiliate Links – Link Cloaking and Management Developer Profile
2 plugins · 5K total installs
How We Detect Affiliate Links – Link Cloaking and Management
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/affiliate-links/admin/css/affiliate-links-admin.css/wp-content/plugins/affiliate-links/admin/js/affiliate-links-admin.jsaffiliate-links-css?ver=1.6affiliate-links-js?ver=1.6HTML / DOM Fingerprints
af-link-settingsdata-field-namedata-field-valueafLinksAdmin[af_link]