Agoda Affiliate Partners Text Link Generator Security & Risk Analysis

wordpress.org/plugins/agoda-affiliate-partners-text-link-generator

This tool was built so that our affiliate partners can easily generate text links in Wordpress.

500 active installs v1.0 PHP + WP 3.9.0+ Updated Aug 18, 2017
accommodationagoda-pluginagoda-comsearch-hotelstravel
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Agoda Affiliate Partners Text Link Generator Safe to Use in 2026?

Generally Safe

Score 85/100

Agoda Affiliate Partners Text Link Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "agoda-affiliate-partners-text-link-generator" v1.0 plugin presents a significant security risk due to a high proportion of unprotected entry points. All four identified AJAX handlers lack authentication checks, meaning any authenticated user, including those with low privileges, could potentially trigger these functions. While the plugin shows good practices in other areas like SQL query preparation and output escaping, the absence of authorization on AJAX handlers creates a wide attack surface for privilege escalation or unintended actions.

The taint analysis revealed two flows with unsanitized paths, which, while not classified as critical or high severity, still warrant attention. These could potentially be vectors for path traversal or file inclusion vulnerabilities if not properly handled by the application logic. The plugin's clean vulnerability history is a positive sign, suggesting the developers may have a good understanding of secure coding, but it does not negate the immediate risks identified in the static analysis.

In conclusion, the plugin has strengths in its database interaction and output handling. However, the critical flaw of unprotected AJAX handlers and the presence of unsanitized paths are major security concerns that significantly elevate its risk profile. Immediate attention is required to implement proper authentication and authorization checks on all AJAX endpoints and to sanitize any user-supplied input used in file path operations.

Key Concerns

  • 4 unprotected AJAX handlers
  • 2 flows with unsanitized paths
  • 0 Nonce checks
  • 0 Capability checks
Vulnerabilities
None known

Agoda Affiliate Partners Text Link Generator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Agoda Affiliate Partners Text Link Generator Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
4 prepared
Unescaped Output
3
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

80% prepared5 total queries

Output Escaping

75% escaped12 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
agdtlwp_call_search_api (admin\textlink.php:109)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Agoda Affiliate Partners Text Link Generator Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_agdtlwp_textlink_saveadmin\textlink.php:48
authwp_ajax_agdtlwp_textlink_loadadmin\textlink.php:70
authwp_ajax_agdtlwp_textlink_trackadmin\textlink.php:87
authwp_ajax_agdtlwp_call_search_apiadmin\textlink.php:108
WordPress Hooks 3
actionadmin_headadmin\textlink.php:24
filtermce_external_pluginsadmin\textlink.php:33
filtermce_buttonsadmin\textlink.php:34
Maintenance & Trust

Agoda Affiliate Partners Text Link Generator Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.0
Last updatedAug 18, 2017
PHP min version
Downloads14K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

Agoda Affiliate Partners Text Link Generator Developer Profile

affiliateproduct

1 plugin · 500 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Agoda Affiliate Partners Text Link Generator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/agoda-affiliate-partners-text-link-generator/textlink-items/textlink.css/wp-content/plugins/agoda-affiliate-partners-text-link-generator/textlink-items/textlink.min.js
Script Paths
/wp-content/plugins/agoda-affiliate-partners-text-link-generator/textlink-items/textlink-ajax.min.js
Version Parameters
agoda-affiliate-partners-text-link-generator/textlink-items/textlink.css?ver=agoda-affiliate-partners-text-link-generator/textlink-items/textlink-ajax.min.js?ver=

HTML / DOM Fingerprints

JS Globals
textlink_ajax_object
REST Endpoints
/wp-json/agoda-affiliate-partners-text-link-generator/
FAQ

Frequently Asked Questions about Agoda Affiliate Partners Text Link Generator