Amazon Widgets Shortcodes Security & Risk Analysis

wordpress.org/plugins/amazon-widgets-shortcodes

Keep your time and save your money with these Amazon widgets shortcodes. Standard compliants, easy to use and so on !

40 active installs v1.6.1 PHP + WP 2.5+ Updated Oct 21, 2011
affiliateamazonmonetizationshortcodeshortcodes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Amazon Widgets Shortcodes Safe to Use in 2026?

Generally Safe

Score 85/100

Amazon Widgets Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The "amazon-widgets-shortcodes" plugin version 1.6.1 exhibits a mixed security posture. On one hand, the plugin demonstrates strong adherence to secure coding practices regarding its entry points, with no apparent AJAX handlers, REST API routes, shortcodes, or cron events that could be directly exploited. Furthermore, all observed SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which significantly reduces the attack surface.

However, a critical concern arises from the taint analysis. One flow was identified with unsanitized paths, and this is flagged as a high severity taint flow. This indicates a potential for attackers to manipulate input that could lead to unintended file access or execution, despite the absence of explicit file operation functions in the static analysis. The lack of output escaping on all identified output points is also a significant weakness, suggesting a risk of cross-site scripting (XSS) vulnerabilities. The absence of known CVEs and a clean vulnerability history is positive, implying a generally well-maintained codebase, but it doesn't negate the risks identified in the static and taint analysis.

In conclusion, while the plugin avoids common pitfalls like unpatched vulnerabilities and direct SQL injection, the high-severity taint flow and complete lack of output escaping present substantial security risks that need immediate attention. The plugin's strengths lie in its controlled entry points and secure database interactions, but its weaknesses in input sanitization and output handling make it susceptible to sophisticated attacks.

Key Concerns

  • High severity taint flow with unsanitized paths
  • 0% output escaping on 10 outputs
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

Amazon Widgets Shortcodes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Amazon Widgets Shortcodes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

0% escaped10 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<options> (admin\form\options.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Amazon Widgets Shortcodes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_menuamazon-widgets-shortcodes.php:44
actionwpmu_new_blogamazon-widgets-shortcodes.php:45
filterwhitelist_optionsamazon-widgets-shortcodes.php:46
actionedit_form_advancedamazon-widgets-shortcodes.php:50
actionadmin_noticesamazon-widgets-shortcodes.php:55
filterthe_excerptamazon-widgets-shortcodes.php:69
filterthe_contentamazon-widgets-shortcodes.php:70
filterthe_excerptamazon-widgets-shortcodes.php:83
filterthe_contentamazon-widgets-shortcodes.php:84
actionwp_footeramazon-widgets-shortcodes.php:85
actionwp_footeramazon-widgets-shortcodes.php:92
actioninitamazon-widgets-shortcodes.php:103
Maintenance & Trust

Amazon Widgets Shortcodes Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedOct 21, 2011
PHP min version
Downloads30K

Community Trust

Rating20/100
Number of ratings1
Active installs40
Developer Profile

Amazon Widgets Shortcodes Developer Profile

thom4

3 plugins · 10K total installs

81
trust score
Avg Security Score
90/100
Avg Patch Time
46 days
View full developer profile
Detection Fingerprints

How We Detect Amazon Widgets Shortcodes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Amazon Widgets Shortcodes