
Affiliate Link Plugin from BlashO Security & Risk Analysis
wordpress.org/plugins/affilinkerAffiLinker automatically converts given keywords into Search Engine Friendly Affiliate Links (+colorful interactive links) throughout your blog.
Is Affiliate Link Plugin from BlashO Safe to Use in 2026?
Generally Safe
Score 85/100Affiliate Link Plugin from BlashO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Affilinker v2.2 plugin exhibits a mixed security posture. While the absence of known CVEs and a seemingly small attack surface with no direct AJAX handlers, REST API routes, shortcodes, or cron events are positive indicators, significant concerns arise from the static analysis. The presence of the `create_function` dangerous function is a red flag, as it can be exploited for arbitrary code execution if not handled with extreme care. Furthermore, a low percentage of SQL queries using prepared statements (7%) and a similarly low rate of proper output escaping (15%) suggest a high likelihood of SQL injection and cross-site scripting (XSS) vulnerabilities. The taint analysis revealing two high-severity flows with unsanitized paths corroborates these concerns, indicating potential injection risks.
The plugin's vulnerability history being clear of any recorded CVEs is a strength, suggesting that past issues (if any) have been addressed or that the plugin hasn't attracted significant adversarial attention. However, this absence of history should not overshadow the direct risks identified in the code analysis. The limited number of nonce and capability checks also contribute to a weaker security posture, as these are fundamental WordPress security mechanisms.
In conclusion, while the lack of public vulnerabilities is encouraging, the static analysis highlights critical areas for improvement. The use of dangerous functions, prevalent lack of prepared statements and output escaping, and identified high-severity taint flows present substantial risks that need immediate attention. A robust security audit focusing on these areas is recommended to ensure the plugin's safety.
Key Concerns
- High severity taint flows found
- Dangerous function 'create_function' used
- Low percentage of prepared SQL statements
- Low percentage of properly escaped output
- Low number of nonce checks
- Zero capability checks
Affiliate Link Plugin from BlashO Security Vulnerabilities
Affiliate Link Plugin from BlashO Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Affiliate Link Plugin from BlashO Attack Surface
WordPress Hooks 18
Maintenance & Trust
Affiliate Link Plugin from BlashO Maintenance & Trust
Maintenance Signals
Community Trust
Affiliate Link Plugin from BlashO Alternatives
AffiliateX – Amazon Affiliate Plugin
affiliatex
AffiliateX is the best WordPress Amazon Affiliate Plugin. Create professional affiliate websites with customizable WordPress Amazon Affiliate Blocks.
YITH WooCommerce Affiliates
yith-woocommerce-affiliates
YITH WooCommerce Affiliates allows you to create affiliate profiles and grant your affiliates earnings each time someone purchases from their link.
AffiliatePages – Pros & Cons, Notice, and CTA Blocks for Affiliates
affiliatebooster-blocks
Boost sales with #1 Affiliate Plugin - elevate CTR with sleek Pros & Cons, Notices, Coupons, Columns, Lists, and CTA Blocks.
Affilia – Affiliate Program & Referral Tracking for WordPress
affiliaa-affiliate-program-with-mlm
Launch a powerful, self-hosted affiliate program for WordPress. Track referrals, manage affiliates, and boost sales for WooCommerce, EDD, and Contact …
Amazing Affiliates – Toolkit for Amazon Associates with Amazon Product Blocks and PAAPI5 Amazon API integration
amazingaffiliates
Monetize your Amazon Affiliate Income with Amazon API Integration & Amazon Product Blocks!
Affiliate Link Plugin from BlashO Developer Profile
2 plugins · 20 total installs
How We Detect Affiliate Link Plugin from BlashO
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
cwdata-affilinkeraffl_link_settings