
Amazon Search Security & Risk Analysis
wordpress.org/plugins/amazon-searchLets you add links to Amazon using a special markup. Also includes an optional widget to search Amazon and display results in your blog.
Is Amazon Search Safe to Use in 2026?
Generally Safe
Score 85/100Amazon Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'amazon-search' v1.2.0 plugin exhibits a mixed security posture. On the positive side, there are no known CVEs in its history and a limited attack surface with some capability checks in place. The presence of a nonce check is also a good security practice. However, significant concerns arise from the static analysis. The fact that 100% of outputs are not properly escaped is a critical weakness, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without sanitization. Furthermore, the taint analysis reveals two high-severity flows with unsanitized paths, which could indicate vulnerabilities if these paths involve user input or sensitive operations. While direct SQL injection is partially mitigated by prepared statements, the remaining unescaped outputs and unsanitized taint flows are substantial risks.
Despite the lack of historical vulnerabilities and a seemingly controlled attack surface, the current code analysis flags serious issues. The absence of proper output escaping across all analyzed outputs is a glaring security flaw that could be easily exploited. The high-severity taint flows are also a direct indication of potential vulnerabilities within the code itself, even if they haven't manifested as CVEs yet. The plugin demonstrates some good security practices but suffers from critical oversights in output sanitization and handling of potentially tainted data flows, which significantly lowers its overall security rating.
Key Concerns
- 0% output escaping
- 2 high severity taint flows
- 37.5% raw SQL (2/8) + 1 non-prepared
Amazon Search Security Vulnerabilities
Amazon Search Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Amazon Search Attack Surface
WordPress Hooks 9
Maintenance & Trust
Amazon Search Maintenance & Trust
Maintenance Signals
Community Trust
Amazon Search Alternatives
Amazon Product in a Post Plugin
amazon-product-in-a-post-plugin
Add formatted Amazon Products to any page or post using the Amazon Product Advertising API.
Add & Replace Affiliate Links for Amazon
add-replace-affiliate-links-for-amazon
Add & Replace Affiliate Links for Amazon plugin helps you to add or update Amazon Associate tag parameters in links.
Amazing Affiliates – Toolkit for Amazon Associates with Amazon Product Blocks and PAAPI5 Amazon API integration
amazingaffiliates
Monetize your Amazon Affiliate Income with Amazon API Integration & Amazon Product Blocks!
Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate
spreadr-for-woocomerce
Spreadr enables WooCommerce merchants to find and sell products from Amazon. To learn more about Spreadr, visit https://spreadr.co/woocommerce
AmaSync – Amazon Product Importer & Affiliate for WooCommerce
affiliate-products-importer-for-woocommerce
Easily import Amazon affiliate products into your WooCommerce store.
Amazon Search Developer Profile
1 plugin · 10 total installs
How We Detect Amazon Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/amazon-search/css/default.css/wp-content/plugins/amazon-search/css/default.css.map/wp-content/plugins/amazon-search/js/amz-search.js/wp-content/plugins/amazon-search/xsl/wp-amz-search.xsl/wp-content/plugins/amazon-search/js/amz-search.jsamazon-search/css/default.css?ver=amazon-search/js/amz-search.js?ver=HTML / DOM Fingerprints
<!-- Amazon Search vAmazon Search vAssociate IDsDefault+3 morename="new_prefs[default_server]"name="usertag[]"name="new_prefs[contribute]"name="new_prefs[default_category]"name="new_prefs[default_search]"name="new_prefs[default_server]"+7 morewindow.amz_search_options[amazon[/amazon]Amazon Searchproduct_description