Disclaimify – Affiliate Disclosure / Disclaimer for WordPress Security & Risk Analysis

wordpress.org/plugins/disclaimify

Disclaimify is the ultimate solution to add affiliate disclosure statements & inform your readers about affiliate links while ensuring transparency.

400 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Dec 2, 2025
affiliateaffiliate-marketingdisclaimerdisclosuredisclosure-statement
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Disclaimify – Affiliate Disclosure / Disclaimer for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

Disclaimify – Affiliate Disclosure / Disclaimer for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The disclaimify v1.0.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, file operations, and the use of prepared statements for all SQL queries are strong indicators of secure coding practices. The high percentage of properly escaped output further mitigates risks of cross-site scripting vulnerabilities. The plugin also benefits from a very small attack surface with no identified unprotected entry points. Furthermore, the plugin has no known historical vulnerabilities, suggesting a history of secure development and maintenance.

However, there are a couple of areas that warrant attention. The complete absence of nonce checks and capability checks across all entry points is a significant concern. While the current static analysis shows no unprotected AJAX handlers or REST API routes, the lack of these fundamental security mechanisms makes the plugin susceptible to CSRF (Cross-Site Request Forgery) attacks and unauthorized actions if any functionality were to be exposed in the future without proper authorization checks. The taint analysis showing zero flows analyzed means that the absence of identified taint flows might be due to the analysis scope rather than definitive proof of their absence. The single shortcode presents a potential, albeit small, attack vector that lacks crucial security checks.

In conclusion, disclaimify v1.0.0 has a strong foundation in secure coding for database operations and output handling. Its clean vulnerability history is a positive sign. The primary weakness lies in the lack of essential security checks like nonces and capability checks, which, if not addressed, could lead to vulnerabilities if the plugin's functionality evolves or if any of its entry points are inadvertently exposed without proper authorization. The plugin is currently considered low risk due to its limited attack surface and lack of known vulnerabilities, but the missing nonce and capability checks represent a potential weakness.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
  • Shortcode present without specific auth checks indicated
Vulnerabilities
None known

Disclaimify – Affiliate Disclosure / Disclaimer for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Disclaimify – Affiliate Disclosure / Disclaimer for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
30 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped31 total outputs
Attack Surface

Disclaimify – Affiliate Disclosure / Disclaimer for WordPress Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[disclaimify] includes\shortcode.php:38
WordPress Hooks 15
actionadmin_enqueue_scriptsincludes\assets.php:38
actionwp_enqueue_scriptsincludes\assets.php:39
actioninitincludes\base.php:36
actioninitincludes\base.php:37
actioninitincludes\base.php:38
filterdisclaimify_filter_for_meta_supportincludes\base.php:72
filterdisclaimify_filter_for_labelsincludes\base.php:89
filterthe_contentincludes\frontend.php:38
filterblocksy:post-meta:itemsincludes\frontend.php:40
actionadd_meta_boxesincludes\metabox.php:204
actionsave_postincludes\metabox.php:205
actioninitincludes\post-type.php:36
filtermanage_disclaimify_posts_columnsincludes\post-type.php:37
filtermanage_disclaimify_posts_custom_columnincludes\post-type.php:38
filtermanage_edit-disclaimify_sortable_columnsincludes\post-type.php:39
Maintenance & Trust

Disclaimify – Affiliate Disclosure / Disclaimer for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs400
Developer Profile

Disclaimify – Affiliate Disclosure / Disclaimer for WordPress Developer Profile

HasThemes

14 plugins · 16K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
179 days
View full developer profile
Detection Fingerprints

How We Detect Disclaimify – Affiliate Disclosure / Disclaimer for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/disclaimify/assets/css/style-frontend.css/wp-content/plugins/disclaimify/assets/css/style.css/wp-content/plugins/disclaimify/assets/js/main.js
Version Parameters
disclaimify-styledisclaimify-main

HTML / DOM Fingerprints

Shortcode Output
[disclaimify id=
FAQ

Frequently Asked Questions about Disclaimify – Affiliate Disclosure / Disclaimer for WordPress