
Disclaimify – Affiliate Disclosure / Disclaimer for WordPress Security & Risk Analysis
wordpress.org/plugins/disclaimifyDisclaimify is the ultimate solution to add affiliate disclosure statements & inform your readers about affiliate links while ensuring transparency.
Is Disclaimify – Affiliate Disclosure / Disclaimer for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Disclaimify – Affiliate Disclosure / Disclaimer for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The disclaimify v1.0.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, file operations, and the use of prepared statements for all SQL queries are strong indicators of secure coding practices. The high percentage of properly escaped output further mitigates risks of cross-site scripting vulnerabilities. The plugin also benefits from a very small attack surface with no identified unprotected entry points. Furthermore, the plugin has no known historical vulnerabilities, suggesting a history of secure development and maintenance.
However, there are a couple of areas that warrant attention. The complete absence of nonce checks and capability checks across all entry points is a significant concern. While the current static analysis shows no unprotected AJAX handlers or REST API routes, the lack of these fundamental security mechanisms makes the plugin susceptible to CSRF (Cross-Site Request Forgery) attacks and unauthorized actions if any functionality were to be exposed in the future without proper authorization checks. The taint analysis showing zero flows analyzed means that the absence of identified taint flows might be due to the analysis scope rather than definitive proof of their absence. The single shortcode presents a potential, albeit small, attack vector that lacks crucial security checks.
In conclusion, disclaimify v1.0.0 has a strong foundation in secure coding for database operations and output handling. Its clean vulnerability history is a positive sign. The primary weakness lies in the lack of essential security checks like nonces and capability checks, which, if not addressed, could lead to vulnerabilities if the plugin's functionality evolves or if any of its entry points are inadvertently exposed without proper authorization. The plugin is currently considered low risk due to its limited attack surface and lack of known vulnerabilities, but the missing nonce and capability checks represent a potential weakness.
Key Concerns
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
- Shortcode present without specific auth checks indicated
Disclaimify – Affiliate Disclosure / Disclaimer for WordPress Security Vulnerabilities
Disclaimify – Affiliate Disclosure / Disclaimer for WordPress Code Analysis
Output Escaping
Disclaimify – Affiliate Disclosure / Disclaimer for WordPress Attack Surface
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
Disclaimify – Affiliate Disclosure / Disclaimer for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Disclaimify – Affiliate Disclosure / Disclaimer for WordPress Alternatives
WP Affiliate Disclosure
wp-affiliate-disclosure
Automatically add a customizable, FTC-compliant disclosure statement across your WordPress website based on the rule(s) you define.
Affiliate Notice Manager
affiliate-notice-manager
This plugin helps to display affiliate disclosure on WordPress Single Posts. It's easy to setup and customize with any latest WordPress Version.
MWW Disclaimer Buttons
mww-disclaimer-buttons
The FTC requires that you put disclosures at the top of your post if you were compensated in any way (affiliate links, free products, or payment).
Affiliate Disclosure and Disclaimer – Affylite
affylite
Affylite - Easy Affiliate Disclosure and Disclaimer
Coderlift Affiliate Compliance
coderlift-affiliate-compliance
This plugin automatically tracks the affiliate links from your post contents and shows a disclaimer message if links found.
Disclaimify – Affiliate Disclosure / Disclaimer for WordPress Developer Profile
14 plugins · 16K total installs
How We Detect Disclaimify – Affiliate Disclosure / Disclaimer for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/disclaimify/assets/css/style-frontend.css/wp-content/plugins/disclaimify/assets/css/style.css/wp-content/plugins/disclaimify/assets/js/main.jsdisclaimify-styledisclaimify-mainHTML / DOM Fingerprints
[disclaimify id=