Affiliates eShop Integration Light Security & Risk Analysis

wordpress.org/plugins/affiliates-eshop-light

This plugin integrates Affiliates with eShop.

10 active installs v1.0.7 PHP + WP 3.5.1+ Updated Dec 14, 2013
adsadvertisingaffiliateaffiliate-marketingaffiliate-plugin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Affiliates eShop Integration Light Safe to Use in 2026?

Generally Safe

Score 85/100

Affiliates eShop Integration Light has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The static analysis of affiliates-eshop-light v1.0.7 reveals a generally strong security posture. The plugin exhibits good practices by not exposing direct entry points like AJAX handlers, REST API routes, or shortcodes without authentication checks, and all identified SQL queries are properly prepared. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a reduced attack surface. However, a concerning area is the output escaping, where only 70% of outputs are properly escaped, leaving 30% potentially vulnerable to cross-site scripting (XSS) attacks. While the plugin has a clean vulnerability history with no known CVEs, the presence of unescaped output is a significant weakness that requires attention.

Despite the positive indicators like proper SQL handling and lack of critical taint flows, the 30% of unescaped output represents a tangible risk. This could allow attackers to inject malicious scripts into the site's frontend, leading to various security issues like session hijacking or defacement. The lack of documented vulnerabilities in the past is a positive sign, but it does not negate the current risks identified in the code. Therefore, while the plugin has a solid foundation, the unescaped output poses a moderate risk that should be addressed.

Key Concerns

  • Unescaped output (30% of outputs)
Vulnerabilities
None known

Affiliates eShop Integration Light Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Affiliates eShop Integration Light Release Timeline

v1.0.7Current
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Affiliates eShop Integration Light Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
3
7 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

70% escaped10 total outputs
Attack Surface

Affiliates eShop Integration Light Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_noticesaffiliates-eshop-light.php:60
actioneshoporderhandleaffiliates-eshop-light.php:91
actionaffiliates_admin_menuaffiliates-eshop-light.php:93
filteraffiliates_footeraffiliates-eshop-light.php:94
Maintenance & Trust

Affiliates eShop Integration Light Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedDec 14, 2013
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Affiliates eShop Integration Light Developer Profile

itthinx

30 plugins · 23K total installs

97
trust score
Avg Security Score
96/100
Avg Patch Time
3 days
View full developer profile
Detection Fingerprints

How We Detect Affiliates eShop Integration Light

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliates-eshop-light/admin/affiliates-eshop-light-admin.css/wp-content/plugins/affiliates-eshop-light/admin/affiliates-eshop-light-admin.js
Script Paths
/wp-content/plugins/affiliates-eshop-light/admin/affiliates-eshop-light-admin.js

HTML / DOM Fingerprints

CSS Classes
manage
Data Attributes
name="options"value="
FAQ

Frequently Asked Questions about Affiliates eShop Integration Light