
AffiliateImporterAm Security & Risk Analysis
wordpress.org/plugins/affiliateimporteramThis plugin allows you to import the products directly from Amazon in your Wordpress WooCommerce store and earn a commission!
Is AffiliateImporterAm Safe to Use in 2026?
Generally Safe
Score 85/100AffiliateImporterAm has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "affiliateimporteram" v1.0.6 plugin exhibits a concerning security posture, primarily due to a large, unprotected attack surface. All 22 identified AJAX handlers lack authentication checks, meaning any authenticated user could potentially trigger these actions, leading to unauthorized operations. Furthermore, the presence of 7 dangerous function calls, specifically "unserialize", combined with 16 unsanitized path taint flows of high severity, indicates a significant risk of remote code execution or data manipulation if these vulnerabilities can be exploited. The low percentage of properly escaped outputs (44%) also raises concerns about potential Cross-Site Scripting (XSS) vulnerabilities.
While the plugin has no recorded vulnerability history, this is not indicative of a secure product given the critical flaws found in the static analysis. The lack of capability checks and only a single nonce check across the entire plugin further exacerbate the risks associated with the unprotected AJAX endpoints. The plugin's strengths are minimal in the context of security, with no bundled libraries to maintain and a moderate use of prepared statements for SQL queries. However, these strengths are overshadowed by the critical security weaknesses, making this plugin a high-risk addition to any WordPress site.
Key Concerns
- 22 AJAX handlers without auth checks
- 6 High severity taint flows
- 7 Dangerous functions (unserialize)
- 16 Flows with unsanitized paths
- Only 1 nonce check
- 0 Capability checks
- 44% Properly escaped outputs
AffiliateImporterAm Security Vulnerabilities
AffiliateImporterAm Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
AffiliateImporterAm Attack Surface
AJAX Handlers 22
WordPress Hooks 36
Scheduled Events 3
Maintenance & Trust
AffiliateImporterAm Maintenance & Trust
Maintenance Signals
Community Trust
AffiliateImporterAm Alternatives
AffiliateImporterAI
affiliateimporteral
This plugin allows you to import the products directly from AliExpress in your Wordpress WooCommerce store and earn a commission!
AffiliateImporterBg
affiliateimporterbg
This plugin allows you to import the products directly from Banggood in your Wordpress WooCommerce store and earn a commission!
Zonify – Amazon Product Importer for WooCommerce
zonify
Import Amazon products into WooCommerce and optionally redirect customers to Amazon using affiliate links.
Quick Product Importer
quick-product-importer
Import products from Amazon, Flipkart, Meesho, and other e-commerce sites automatically without API. Light version with single import.
Storage for Woo via S3-Compatible
storage-for-woo-via-s3-compatible
Enable secure cloud storage and delivery of your WooCommerce digital products through S3-Compatible storage.
AffiliateImporterAm Developer Profile
4 plugins · 50 total installs
How We Detect AffiliateImporterAm
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/affiliateimporteram/assets/css/dnolbon.css/wp-content/plugins/affiliateimporteram/assets/css/style.css/wp-content/plugins/affiliateimporteram/assets/css/font-awesome.min.css/wp-content/plugins/affiliateimporteram/assets/js/datetimepicker/jquery.datetimepicker.css/wp-content/plugins/affiliateimporteram/assets/js/lighttabs/lighttabs.css/wp-content/plugins/affiliateimporteram/assets/js/script.js/wp-content/plugins/affiliateimporteram/assets/js/datetimepicker/jquery.datetimepicker.js/wp-content/plugins/affiliateimporteram/assets/js/lighttabs/lighttabs.js+1 moreassets/js/script.jsassets/js/datetimepicker/jquery.datetimepicker.jsassets/js/lighttabs/lighttabs.jsassets/js/DnolbonColumns.jsaffiliateimporteram/assets/css/dnolbon.css?ver=affiliateimporteram/assets/css/style.css?ver=affiliateimporteram/assets/css/font-awesome.min.css?ver=affiliateimporteram/assets/js/datetimepicker/jquery.datetimepicker.css?ver=affiliateimporteram/assets/js/lighttabs/lighttabs.css?ver=affiliateimporteram/assets/js/script.js?ver=affiliateimporteram/assets/js/datetimepicker/jquery.datetimepicker.js?ver=affiliateimporteram/assets/js/lighttabs/lighttabs.js?ver=affiliateimporteram/assets/js/DnolbonColumns.js?ver=HTML / DOM Fingerprints
WPURLS