Amazon Ranking Security & Risk Analysis

wordpress.org/plugins/amazon-ranking

This widget shows Amazon Bestsellers, Hot New Releases, Most Gifted and Most Wished For.

10 active installs v1.0.2 PHP + WP 2.8+ Updated Dec 5, 2012
affiliateamazonsidebarwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Amazon Ranking Safe to Use in 2026?

Generally Safe

Score 85/100

Amazon Ranking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "amazon-ranking" plugin v1.0.2 exhibits a strong security posture based on the static analysis provided. The complete absence of direct attack surface entries like AJAX handlers, REST API routes, and shortcodes significantly limits potential entry points for attackers. Furthermore, the fact that all SQL queries utilize prepared statements is an excellent practice, mitigating the risk of SQL injection vulnerabilities. The lack of dangerous functions and file operations also contributes positively to its security. However, a significant concern arises from the output escaping. With 25 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data rendered on the frontend without proper sanitization could be exploited to inject malicious scripts.

Key Concerns

  • No output escaping
Vulnerabilities
None known

Amazon Ranking Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Amazon Ranking Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped25 total outputs
Attack Surface

Amazon Ranking Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initks-amazon-ranking.php:308
Maintenance & Trust

Amazon Ranking Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedDec 5, 2012
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Amazon Ranking Developer Profile

kenichisak

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Amazon Ranking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
widget_ks_amazon_ranking
FAQ

Frequently Asked Questions about Amazon Ranking