Amazon Affiliate Link Globalizer Security & Risk Analysis

wordpress.org/plugins/amazon-affiliate-link-globalizer

Rewrites Amazon.com/Amzn.com and forwards the visitor to 'their' country specific Amazon store (using IP Geolocation).

70 active installs v1.3 PHP + WP 2.8+ Updated Jun 6, 2016
amazonamazon-affiliateamazon-associatesamazon-localizeramazon-partner
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Amazon Affiliate Link Globalizer Safe to Use in 2026?

Generally Safe

Score 85/100

Amazon Affiliate Link Globalizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "amazon-affiliate-link-globalizer" plugin v1.3 exhibits a generally strong security posture based on the provided static analysis. The absence of known vulnerabilities, critical taint flows, dangerous functions, and direct SQL queries is highly positive. Furthermore, the plugin appears to have a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events directly exposed without authentication or permission checks. This suggests diligent effort in limiting potential entry points for attackers.

However, a significant concern arises from the output escaping. With 100% of outputs not being properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any data processed or displayed by the plugin, if not rigorously sanitized before output, could be manipulated by an attacker to inject malicious scripts, potentially leading to session hijacking or other harmful actions. While the plugin has a capability check, this does not mitigate the risk of XSS if the output is consistently unescaped. The lack of vulnerability history is a good sign, but it does not eliminate the inherent risks identified in the code analysis.

Key Concerns

  • Output escaping is not implemented (100%)
Vulnerabilities
None known

Amazon Affiliate Link Globalizer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Amazon Affiliate Link Globalizer Release Timeline

v1.3Current
v1.2
v1.1
Code Analysis
Analyzed Mar 16, 2026

Amazon Affiliate Link Globalizer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

Amazon Affiliate Link Globalizer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initamazon-link-globalizer.php:52
actionadmin_menuamazon-link-globalizer.php:53
filterthe_contentamazon-link-globalizer.php:54
Maintenance & Trust

Amazon Affiliate Link Globalizer Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedJun 6, 2016
PHP min version
Downloads13K

Community Trust

Rating62/100
Number of ratings8
Active installs70
Developer Profile

Amazon Affiliate Link Globalizer Developer Profile

guruz

1 plugin · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Amazon Affiliate Link Globalizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Amazon Affiliate Link Globalizer