
Amazon Machine Tags Security & Risk Analysis
wordpress.org/plugins/amazon-machine-tagsThe plugin checks for machine tags with ISBN or ASIN numbers, gets the product data from Amazon, and displays it in the sidebar or in a blog article.
Is Amazon Machine Tags Safe to Use in 2026?
Generally Safe
Score 100/100Amazon Machine Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "amazon-machine-tags" plugin version 3.0.2 exhibits a generally positive security posture based on the static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with exposed entry points is a significant strength. Furthermore, the analysis indicates no dangerous functions, no raw SQL queries (all prepared statements), and no identified taint flows. This suggests that the core code likely avoids common attack vectors like SQL injection and cross-site scripting (XSS) from direct code execution.
However, there are notable concerns. The output escaping is severely lacking, with only 7% of outputs being properly escaped. This represents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. The plugin also performs file operations and makes external HTTP requests, which, without proper sanitization or validation (not explicitly detailed but implied by low escaping percentage), could lead to security issues. The complete lack of nonce and capability checks, especially in conjunction with file operations and external requests, is a major red flag, leaving these actions potentially vulnerable to unauthorized access or manipulation.
The plugin's vulnerability history is clean, with zero recorded CVEs. While this is excellent, it does not negate the identified risks within the current codebase. The strengths lie in its minimal attack surface and the use of prepared statements. The critical weaknesses are the poor output escaping and the absence of authorization checks, which are fundamental security practices. The overall risk is moderate, leaning towards higher due to the significant XSS potential.
Key Concerns
- Low output escaping percentage
- No nonce checks
- No capability checks
- File operations without clear auth checks
- External HTTP requests without clear auth checks
Amazon Machine Tags Security Vulnerabilities
Amazon Machine Tags Code Analysis
Output Escaping
Amazon Machine Tags Attack Surface
WordPress Hooks 5
Maintenance & Trust
Amazon Machine Tags Maintenance & Trust
Maintenance Signals
Community Trust
Amazon Machine Tags Alternatives
REST API Post Embeds
rest-api-post-embeds
Embed posts from your site or others' into your posts and pages.
Display Post Feed from Medium
display-post-feed-from-medium
Display Post Feed from Medium is a WordPress plugin to display the posts/articles from medium.com on any page/post via the shortcode.
Init View Count – AI-Powered, Trending, REST API
init-view-count
Count post views accurately via REST API with customizable display. Lightweight, fast, and extensible. Includes shortcode with multiple layouts.
IA Escritora Connector
ia-escritora-connector
Este plugin permite conexões seguras com a API IA Escritora para criação automatizada de posts.
WP REST API – Filter posts date wise using given column
wp-rest-api-filter-posts-date-wise-using-given-column
In WordPress 4.7, Posts cannot be filtered based on modified, modified_gmt, date_gmt fields.
Amazon Machine Tags Developer Profile
1 plugin · 10 total installs
How We Detect Amazon Machine Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/amazon-machine-tags/amtap-admin.css/wp-content/plugins/amazon-machine-tags/amtap-blog.css/wp-content/plugins/amazon-machine-tags/amtap.js/wp-content/plugins/amazon-machine-tags/amtap.jsamazon-machine-tags/amtap-admin.css?ver=amazon-machine-tags/amtap-blog.css?ver=amazon-machine-tags/amtap.js?ver=HTML / DOM Fingerprints
amtap-admin-wrapperamtap-headlineamtap-itemamtap-imageamtap-priceamtap-titleamtap-starsamtap-reviewsDebug XML: <!-- AMTAP: NO RESULT --><!-- AMTAP: NO RESULT --><!-- AMTAP: NO RESULT -->+1 moredata-amtap-iddata-amtap-titledata-amtap-imagedata-amtap-pricedata-amtap-starsdata-amtap-reviewsamtap[amazon-tags]