Affiliate Link Plugin from BlashO Security & Risk Analysis

wordpress.org/plugins/affilinker

AffiLinker automatically converts given keywords into Search Engine Friendly Affiliate Links (+colorful interactive links) throughout your blog.

10 active installs v2.2 PHP 5.2.4+ WP 3.0+ Updated Jan 15, 2018
affiliateaffiliate-pluginaffilinkerblashotag-cloud
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Affiliate Link Plugin from BlashO Safe to Use in 2026?

Generally Safe

Score 85/100

Affiliate Link Plugin from BlashO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The Affilinker v2.2 plugin exhibits a mixed security posture. While the absence of known CVEs and a seemingly small attack surface with no direct AJAX handlers, REST API routes, shortcodes, or cron events are positive indicators, significant concerns arise from the static analysis. The presence of the `create_function` dangerous function is a red flag, as it can be exploited for arbitrary code execution if not handled with extreme care. Furthermore, a low percentage of SQL queries using prepared statements (7%) and a similarly low rate of proper output escaping (15%) suggest a high likelihood of SQL injection and cross-site scripting (XSS) vulnerabilities. The taint analysis revealing two high-severity flows with unsanitized paths corroborates these concerns, indicating potential injection risks.

The plugin's vulnerability history being clear of any recorded CVEs is a strength, suggesting that past issues (if any) have been addressed or that the plugin hasn't attracted significant adversarial attention. However, this absence of history should not overshadow the direct risks identified in the code analysis. The limited number of nonce and capability checks also contribute to a weaker security posture, as these are fundamental WordPress security mechanisms.

In conclusion, while the lack of public vulnerabilities is encouraging, the static analysis highlights critical areas for improvement. The use of dangerous functions, prevalent lack of prepared statements and output escaping, and identified high-severity taint flows present substantial risks that need immediate attention. A robust security audit focusing on these areas is recommended to ensure the plugin's safety.

Key Concerns

  • High severity taint flows found
  • Dangerous function 'create_function' used
  • Low percentage of prepared SQL statements
  • Low percentage of properly escaped output
  • Low number of nonce checks
  • Zero capability checks
Vulnerabilities
None known

Affiliate Link Plugin from BlashO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Affiliate Link Plugin from BlashO Code Analysis

Dangerous Functions
4
Raw SQL Queries
52
4 prepared
Unescaped Output
172
30 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Dangerous Functions Found

create_function, create_function('$m', 'global $link;global $linkformat;global $linknofollow;global $linklink_targeaffilinker.php:2651
create_function, create_function('$m', 'global $link;global $linkformat4comm;global $linknofollow;global $linklink_affilinker.php:2685
create_function, create_function('$m', 'global $link;global $linkformat;global $linknofollow;global $linklink_targetrunk\affilinker.php:2651
create_function, create_function('$m', 'global $link;global $linkformat4comm;global $linknofollow;global $linklink_trunk\affilinker.php:2685

Bundled Libraries

Select2

SQL Query Safety

7% prepared56 total queries

Output Escaping

15% escaped202 total outputs
Data Flows
8 unsanitized

Data Flow Analysis

12 flows8 with unsanitized paths
widget (affilinker.php:37)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Affiliate Link Plugin from BlashO Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionadmin_initaffilinker.php:10
actionadmin_menuaffilinker.php:11
filterthe_contentaffilinker.php:12
filterget_commentaffilinker.php:13
actionwidgets_initaffilinker.php:315
actioninitaffilinker.php:527
actionwp_footeraffilinker.php:2482
actionwp_footeraffilinker.php:2753
actionwp_footeraffilinker.php:2764
actionadmin_inittrunk\affilinker.php:10
actionadmin_menutrunk\affilinker.php:11
filterthe_contenttrunk\affilinker.php:12
filterget_commenttrunk\affilinker.php:13
actionwidgets_inittrunk\affilinker.php:315
actioninittrunk\affilinker.php:527
actionwp_footertrunk\affilinker.php:2482
actionwp_footertrunk\affilinker.php:2753
actionwp_footertrunk\affilinker.php:2764
Maintenance & Trust

Affiliate Link Plugin from BlashO Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 15, 2018
PHP min version5.2.4
Downloads11K

Community Trust

Rating60/100
Number of ratings4
Active installs10
Developer Profile

Affiliate Link Plugin from BlashO Developer Profile

Ven Tesh

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Affiliate Link Plugin from BlashO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
cw
Data Attributes
data-affilinker
JS Globals
affl_link_settings
FAQ

Frequently Asked Questions about Affiliate Link Plugin from BlashO