Affiliate program for your website ( integration with Sdelka.biz ) Security & Risk Analysis

wordpress.org/plugins/affiliate-marketing

Плагин интегрирует ваш сайт с платформой партнёрского маркетинга Sdelka.biz.

10 active installs v1.1.20 PHP 5.2+ WP 4.7+ Updated Jul 15, 2023
%d0%bf%d0%b0%d1%80%d1%82%d0%bd%d1%91%d1%80%d0%ba%d0%b0%d0%bf%d0%b0%d1%80%d1%82%d0%bd%d1%91%d1%80%d1%81%d0%ba%d0%b0%d1%8f-%d0%bf%d1%80%d0%be%d0%b3%d1%80%d0%b0%d0%bc%d0%bc%d0%b0%d0%bf%d0%bb%d0%b0%d0%b3%d0%b8%d0%bd-%d0%b4%d0%bb%d1%8f-%d0%bf%d0%b0%d1%80%d1%82%d0%bd%d1%91%d1%80%d1%81%d0%ba%d0%be%d0%b9-%d0%bf%d1%80%d0%be%d0%b3%d1%80%d0%b0%d0%bc%d0%bc%d1%8b%d1%80%d0%b5%d1%84%d0%b5%d1%80%d0%b0%d0%bb%d1%8c%d0%bd%d0%b0%d1%8f-%d0%bf%d1%80%d0%be%d0%b3%d1%80%d0%b0%d0%bc%d0%bc%d0%b0sdelka
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Affiliate program for your website ( integration with Sdelka.biz ) Safe to Use in 2026?

Generally Safe

Score 85/100

Affiliate program for your website ( integration with Sdelka.biz ) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The affiliate-marketing plugin v1.1.20 exhibits a generally good security posture, with no known historical vulnerabilities and a clean slate regarding critical code signals. The absence of dangerous functions, raw SQL queries, and file operations is commendable. However, several areas raise concerns. The plugin makes 5 external HTTP requests, which can be a vector for various attacks if not handled securely, especially if the target URLs are user-controlled or untrusted. The significant percentage of unescaped output (37%) is a notable weakness, potentially leading to Cross-Site Scripting (XSS) vulnerabilities if sensitive data is not properly sanitized before display.

The taint analysis, while reporting no critical or high severity flows, did identify two flows with unsanitized paths. This indicates a potential for path traversal vulnerabilities, even if they haven't escalated to critical levels in static analysis. The complete lack of nonce and capability checks across all entry points (AJAX, REST API, shortcodes, cron) is a major security gap. This means that any action initiated through these mechanisms could be performed by unauthenticated or unauthorized users, opening the door to privilege escalation or unauthorized data manipulation.

While the plugin has no recorded vulnerability history, the static analysis reveals significant potential weaknesses that could easily be exploited. The lack of authentication and authorization checks on all entry points, combined with the unsanitized path flows and unescaped output, suggest a high risk of exploitation for XSS, privilege escalation, and potentially other vulnerabilities. The external HTTP requests also add to the overall risk profile.

Key Concerns

  • Unsanitized paths found in taint analysis
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Unescaped output identified
  • External HTTP requests made
Vulnerabilities
None known

Affiliate program for your website ( integration with Sdelka.biz ) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Affiliate program for your website ( integration with Sdelka.biz ) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

63% escaped8 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
update_sdelka_settings (includes\class-sdelka.php:322)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Affiliate program for your website ( integration with Sdelka.biz ) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionplugins_loadedincludes\class-sdelka.php:141
actionadmin_enqueue_scriptsincludes\class-sdelka.php:156
actionadmin_enqueue_scriptsincludes\class-sdelka.php:157
actionwoocommerce_order_status_completedincludes\class-sdelka.php:161
actionwoocommerce_order_status_cancelledincludes\class-sdelka.php:162
actionwoocommerce_order_status_failedincludes\class-sdelka.php:163
actionwoocommerce_order_status_refundedincludes\class-sdelka.php:164
actionwp_enqueue_scriptsincludes\class-sdelka.php:180
actionwp_enqueue_scriptsincludes\class-sdelka.php:181
actionwoocommerce_new_orderincludes\class-sdelka.php:183
actionadmin_menuincludes\class-sdelka.php:196
actionplugin_action_links_sdelka/sdelka.phpincludes\class-sdelka.php:199
actionwidgets_initincludes\class-sdelka.php:202
Maintenance & Trust

Affiliate program for your website ( integration with Sdelka.biz ) Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJul 15, 2023
PHP min version5.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Affiliate program for your website ( integration with Sdelka.biz ) Alternatives

No alternatives data available yet.

Developer Profile

Affiliate program for your website ( integration with Sdelka.biz ) Developer Profile

sdelka

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Affiliate program for your website ( integration with Sdelka.biz )

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliate-marketing/css/sdelka-admin.css/wp-content/plugins/affiliate-marketing/js/sdelka-admin.js
Version Parameters
affiliate-marketing/css/sdelka-admin.css?ver=affiliate-marketing/js/sdelka-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Affiliate program for your website ( integration with Sdelka.biz )