
Eldolink® Security & Risk Analysis
wordpress.org/plugins/eldolinkEldolink® is an affiliate program that allows you to monetize your traffic. Original wellness contents & products. Win big with Slimdoo®.
Is Eldolink® Safe to Use in 2026?
Generally Safe
Score 85/100Eldolink® has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The eldolink v1.7 plugin exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The complete absence of known CVEs and a clean taint analysis suggest a well-maintained and secure codebase. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries. However, there are notable areas for improvement. The low percentage of properly escaped output (34%) presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the presence of external HTTP requests which could potentially be influenced by user input. Furthermore, the complete lack of nonce and capability checks across all entry points (AJAX, REST API, shortcodes, cron events) indicates a substantial lack of authentication and authorization validation, leaving the plugin vulnerable to unauthorized actions and privilege escalation if any of its entry points are exploitable. The presence of external HTTP requests without explicit security checks also warrants careful consideration for potential SSRF or information disclosure risks. While the plugin is currently uncompromised, these unaddressed security weaknesses, particularly the output escaping and lack of authorization checks, represent potential vectors for future exploitation.
Key Concerns
- Low output escaping percentage
- No nonce checks on entry points
- No capability checks on entry points
- External HTTP requests without clear validation
Eldolink® Security Vulnerabilities
Eldolink® Release Timeline
Eldolink® Code Analysis
Output Escaping
Eldolink® Attack Surface
Shortcodes 5
WordPress Hooks 11
Maintenance & Trust
Eldolink® Maintenance & Trust
Maintenance Signals
Community Trust
Eldolink® Alternatives
LWS Affiliation
lws-affiliation
Add banners and widgets from the affiliate program of LWS.
Goracash
goracash
Goracash, part of Wengo - Vivendi Group, is an affiliate program that allows you to monetize your traffic and earn money with it.
AdSpeed Ad Server
adspeed-ad-server
This plugin displays ads from your AdSpeed account on the sidebar or within a post. Ads are served, managed and tracked for impressions and clicks by …
CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice)
cookie-law-info
Easily set up cookie banner or notice in WordPress, and policy pages for compliance with global cookie laws (GDPR, DSGVO, RGPD, CCPA/CPRA, etc).
CookieAdmin – Cookie Consent Banner
cookieadmin
CookieAdmin provides easy to configure cookie consent banner with GDPR and CCPA law support.
Eldolink® Developer Profile
1 plugin · 10 total installs
How We Detect Eldolink®
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eldolink/js/t.js/wp-content/plugins/eldolink/js/admin.jsHTML / DOM Fingerprints
window.jQueryjQuery.eldolink