Amazon Link Engine Security & Risk Analysis

wordpress.org/plugins/amazon-link-engine

Automatically localize and affiliate Amazon product links to improve user experience, increase conversions and earn global commissions.

2K active installs v1.4.1 PHP + WP 2.7+ Updated Feb 16, 2024
affiliateamazonassociateslocalizeuniversal
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Amazon Link Engine Safe to Use in 2026?

Generally Safe

Score 85/100

Amazon Link Engine has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The plugin "amazon-link-engine" v1.4.1 demonstrates a strong adherence to secure coding practices in several key areas. The static analysis reveals no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. Furthermore, the code employs prepared statements exclusively for its SQL queries, eliminating the risk of SQL injection vulnerabilities related to database interactions. The absence of dangerous functions, file operations, and external HTTP requests also contributes positively to its security posture. The plugin also has no recorded vulnerability history, indicating a stable and secure past.

However, the static analysis raises a significant concern regarding output escaping. With 16 total outputs and 0% properly escaped, there is a high probability of cross-site scripting (XSS) vulnerabilities. Any data displayed to users that originates from external sources or user input, and is not properly escaped, could be manipulated to inject malicious scripts. The complete lack of nonce checks and capability checks across all entry points (though there are none identified) is a missed opportunity for defense-in-depth, and while not an immediate risk due to the absence of entry points, it highlights a potential gap if any were to be introduced in future versions. Overall, while the plugin avoids common pitfalls like SQL injection and has a clean vulnerability record, the critical issue of unescaped output presents a substantial risk that needs immediate attention.

Key Concerns

  • Output escaping is not properly implemented
Vulnerabilities
None known

Amazon Link Engine Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Amazon Link Engine Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped16 total outputs
Attack Surface

Amazon Link Engine Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwp_enqueue_scriptsamazon-link-engine.php:31
actionadmin_enqueue_scriptsamazon-link-engine.php:32
actionadmin_initamazon-link-engine.php:327
actionadmin_menuamazon-link-engine.php:328
actionadmin_noticesamazon-link-engine.php:329
actionwp_headamazon-link-engine.php:333
actionplugins_loadedamazon-link-engine.php:352
Maintenance & Trust

Amazon Link Engine Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedFeb 16, 2024
PHP min version
Downloads90K

Community Trust

Rating88/100
Number of ratings31
Active installs2K
Developer Profile

Amazon Link Engine Developer Profile

Geniuslink

2 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Amazon Link Engine

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/amazon-link-engine/js/amazon-link-engine.js/wp-content/plugins/amazon-link-engine/css/amazon-link-engine.css
Script Paths
/wp-content/plugins/amazon-link-engine/js/amazon-link-engine.js
Version Parameters
amazon-link-engine/js/amazon-link-engine.js?ver=amazon-link-engine/css/amazon-link-engine.css?ver=

HTML / DOM Fingerprints

CSS Classes
genius-feedback
HTML Comments
Disabled rating & feedback requestShow Feedback form if it's been X days since signup and they haven't already dismissed it
Data Attributes
data-genius-ale-id
JS Globals
genius_ale_settingsgenius_ale_ajax_object
Shortcode Output
[amazon-link-engine type="image" asin=""[amazon-link-engine type="title" asin=""[amazon-link-engine type="price" asin=""[amazon-link-engine type="all" asin=""
FAQ

Frequently Asked Questions about Amazon Link Engine