AmazoLinkenator Security & Risk Analysis

wordpress.org/plugins/amazolinkenator

Automatically adds your Amazon Affiliate code to any Amazon product URLs on posts, pages, & comments. Optionally shortens URLs.

30 active installs v4.21 PHP 5.6+ WP 4.0.1+ Updated Apr 10, 2024
amazon-affiliate-links-shorten-urls
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AmazoLinkenator Safe to Use in 2026?

Generally Safe

Score 92/100

AmazoLinkenator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "amazolinkenator" v4.21 plugin exhibits a generally strong security posture based on the static analysis. The complete absence of identifiable attack surface points like AJAX handlers, REST API routes, shortcodes, and cron events, especially without authentication checks, significantly limits potential exploitation vectors. Furthermore, the code demonstrates good practices by using prepared statements for all SQL queries and a high percentage of output escaping, mitigating common injection vulnerabilities. The lack of any recorded vulnerabilities, including CVEs, in its history also suggests a history of secure development or a lack of targeted security research.

Despite these positive indicators, there are areas for concern. The complete absence of nonce checks and capability checks is a notable weakness. While the current attack surface is zero, this lack of authorization and integrity checks means that if any entry points were introduced in future updates or through other means, they would be immediately vulnerable. The presence of file operations and external HTTP requests, while not inherently malicious, always carry a risk and should be carefully scrutinized for any unsanitized input that could be leveraged for arbitrary file operations or SSRF attacks. The lack of taint analysis results is also a minor concern; it's possible that complex or less obvious taint flows were not detected by the analysis performed.

In conclusion, "amazolinkenator" v4.21 appears to be a secure plugin in its current state due to its limited attack surface and good data handling practices. However, the complete omission of nonce and capability checks represents a significant oversight that could lead to vulnerabilities if the plugin evolves. The historical absence of vulnerabilities is a strong positive, but it should not lead to complacency, especially given the identified control deficiencies.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Unescaped output (28% of outputs)
Vulnerabilities
None known

AmazoLinkenator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AmazoLinkenator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
2
Bundled Libraries
0

Output Escaping

72% escaped18 total outputs
Attack Surface

AmazoLinkenator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionupgrader_process_completeamazolinkenator.php:51
actionadmin_menuamazolinkenator.php:69
actionadmin_initamazolinkenator.php:70
filterpreprocess_commentamazolinkenator.php:375
filterwp_insert_post_dataamazolinkenator.php:380
actionadmin_noticesamazolinkenator.php:658
Maintenance & Trust

AmazoLinkenator Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 10, 2024
PHP min version5.6
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Alternatives

AmazoLinkenator Alternatives

No alternatives data available yet.

Developer Profile

AmazoLinkenator Developer Profile

Rick Hellewell

16 plugins · 1K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AmazoLinkenator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/amazolinkenator/js/amazonlinkenator.js/wp-content/plugins/amazolinkenator/js/colorbox/jquery.colorbox-min.js/wp-content/plugins/amazolinkenator/js/colorbox/colorbox.css/wp-content/plugins/amazolinkenator/css/settings.css
Script Paths
/wp-content/plugins/amazolinkenator/js/amazonlinkenator.js/wp-content/plugins/amazolinkenator/js/colorbox/jquery.colorbox-min.js
Version Parameters
amazolinkenator/js/amazonlinkenator.js?ver=amazolinkenator/js/colorbox/jquery.colorbox-min.js?ver=amazolinkenator/js/colorbox/colorbox.css?ver=amazolinkenator/css/settings.css?ver=

HTML / DOM Fingerprints

CSS Classes
AZLNK_optionsAZLNK_sidebar
HTML Comments
<!-- amazonlinkenator: enable to start --><!-- amazonlinkenator settings: enable to start --><!-- this is a shortcode for the amazolinkenator plugin. It inserts links to the plugins settings page. --><!-- amazolinkenator: donate to help support -->+1 more
Data Attributes
data-azlnk-iddata-azlnk-affiliatedata-azlnk-targetdata-azlnk-trackdata-azlnk-typedata-azlnk-campaign+1 more
JS Globals
window.amazolinkenator_affiliate_keywindow.amazolinkenator_auto_shortenwindow.amazolinkenator_enable_commentswindow.amazolinkenator_enable_affiliator_postswindow.amazolinkenator_don
Shortcode Output
[amazolinkenator_settings_link]
FAQ

Frequently Asked Questions about AmazoLinkenator