
Frumbik Affiliate Hub – Affiliate Links, Amazon Product Displays, Click Tracking & Geo-Targeting Security & Risk Analysis
wordpress.org/plugins/frumbik-affiliate-hubFree affiliate link management, Amazon product displays, click tracking, and GA4 integration for WordPress.
Is Frumbik Affiliate Hub – Affiliate Links, Amazon Product Displays, Click Tracking & Geo-Targeting Safe to Use in 2026?
Generally Safe
Score 100/100Frumbik Affiliate Hub – Affiliate Links, Amazon Product Displays, Click Tracking & Geo-Targeting has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The frumbik-affiliate-hub plugin v2.1.8 presents a mixed security posture. On the positive side, it demonstrates strong adherence to WordPress security best practices with 100% of its SQL queries using prepared statements and a significant portion of output being properly escaped. The plugin also incorporates a good number of nonce and capability checks, contributing to a generally protected attack surface. Its vulnerability history is remarkably clean, with no recorded CVEs, which suggests a history of responsible development and maintenance.
However, the static analysis reveals several areas of concern. The presence of dangerous functions like `preg_replace(/e)`, `exec`, and `shell_exec` are inherently risky and can be exploited if not handled with extreme care and strict input validation. Furthermore, a high number of taint flows (51) with unsanitized paths, and 45 identified as high severity, indicate a significant risk of input manipulation leading to potentially harmful actions, despite the absence of directly exploitable critical vulnerabilities in this run. The high number of file operations (10) when combined with unsanitized paths is also a red flag that warrants investigation.
In conclusion, while the plugin benefits from excellent SQL handling and a clean CVE history, the identified dangerous functions and numerous high-severity unsanitized taint flows present a considerable risk. The developers have clearly invested in fundamental security practices, but the aforementioned issues necessitate careful scrutiny and potential remediation to achieve a truly robust security profile.
Key Concerns
- High severity unsanitized taint flows
- Presence of dangerous functions (exec, shell_exec)
- Presence of dangerous function (preg_replace(/e))
- Unsanitized paths in taint flows
- High number of file operations
- Bundled library (TinyMCE) could be outdated
Frumbik Affiliate Hub – Affiliate Links, Amazon Product Displays, Click Tracking & Geo-Targeting Security Vulnerabilities
Frumbik Affiliate Hub – Affiliate Links, Amazon Product Displays, Click Tracking & Geo-Targeting Release Timeline
Frumbik Affiliate Hub – Affiliate Links, Amazon Product Displays, Click Tracking & Geo-Targeting Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Frumbik Affiliate Hub – Affiliate Links, Amazon Product Displays, Click Tracking & Geo-Targeting Attack Surface
AJAX Handlers 39
Shortcodes 1
WordPress Hooks 89
Scheduled Events 10
Maintenance & Trust
Frumbik Affiliate Hub – Affiliate Links, Amazon Product Displays, Click Tracking & Geo-Targeting Maintenance & Trust
Maintenance Signals
Community Trust
Frumbik Affiliate Hub – Affiliate Links, Amazon Product Displays, Click Tracking & Geo-Targeting Alternatives
LinkAlert
codirun-linkalert
Link management and click tracking plugin for WordPress. Monitor clicks in real time, manage short links, and receive instant notifications.
Royal Links
royal-links
Free affiliate link management, URL shortener, and link cloaking plugin with geo-targeting, A/B testing, QR codes, and auto-linking. No premium tier.
Click Counter by Simple Tools
click-counter
Advanced click tracking for any CSS selector. Analytics, charts, goals, CSV export, visual picker, and more.
ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing
shortlinkspro
Shorten, track, manage and share any URL using your own domain name!
Smart Click Tracker
smart-click-tracker
Track clicks on any element of your WordPress site and view detailed statistics with beautiful charts.
Frumbik Affiliate Hub – Affiliate Links, Amazon Product Displays, Click Tracking & Geo-Targeting Developer Profile
2 plugins · 40 total installs
How We Detect Frumbik Affiliate Hub – Affiliate Links, Amazon Product Displays, Click Tracking & Geo-Targeting
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/frumbik-affiliate-hub/assets/css/admin-app.css/wp-content/plugins/frumbik-affiliate-hub/assets/css/frontend-app.css/wp-content/plugins/frumbik-affiliate-hub/assets/js/admin-app.js/wp-content/plugins/frumbik-affiliate-hub/assets/js/frontend-app.js/wp-content/plugins/frumbik-affiliate-hub/assets/js/admin-app.js/wp-content/plugins/frumbik-affiliate-hub/assets/js/frontend-app.jsfrumbik-affiliate-hub/assets/css/admin-app.css?ver=frumbik-affiliate-hub/assets/css/frontend-app.css?ver=frumbik-affiliate-hub/assets/js/admin-app.js?ver=frumbik-affiliate-hub/assets/js/frontend-app.js?ver=HTML / DOM Fingerprints
frumbik-affiliate-hub-welcome-screen<!-- Frumbik Affiliate Hub: Options Page --><!-- Frumbik Affiliate Hub: Welcome Page --><!-- Frumbik Affiliate Hub: Link Shortener Settings --><!-- Frumbik Affiliate Hub: Advanced Settings -->+60 moredata-dismiss-key="frumbik_wp_org_notice"window.frumbik_affiliate_hub_admin_paramswindow.frumbik_affiliate_hub_frontend_params