GothAmazon Security & Risk Analysis

wordpress.org/plugins/gothamazon

Optimisez votre Affiliation Amazon comme jamais avec l'un des plugins les plus complets existants ! Développé de A à Z par un SEO qui connait les …

30 active installs v3.5.2 PHP 7.4+ WP 6.0+ Updated Dec 10, 2025
affiliateaffiliationamazonamazon-affiliateecommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GothAmazon Safe to Use in 2026?

Generally Safe

Score 100/100

GothAmazon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'gothamazon' v3.5.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, exclusively using prepared statements for SQL queries, and having no known historical vulnerabilities. This suggests a generally careful development approach concerning core security concerns like data injection and unpatched exploits. However, significant concerns arise from the attack surface analysis, particularly the number of unprotected AJAX handlers and REST API routes. This indicates potential entry points that could be exploited without proper authentication or authorization checks. The taint analysis, while not showing critical or high severity issues, revealed several flows with unsanitized paths, which could still lead to unexpected behavior or potential vulnerabilities if not handled carefully by developers in subsequent code. The limited number of nonces and capability checks further exacerbates the risk associated with the unprotected entry points. In conclusion, while the plugin is strong in areas like SQL security and vulnerability history, the exposed attack surface and unsanitized paths present a notable risk that needs to be addressed to improve its overall security.

Key Concerns

  • Unprotected AJAX handlers
  • Unprotected REST API routes
  • Flows with unsanitized paths
  • Low number of nonce checks
  • Low number of capability checks
  • Moderate percentage of unescaped output
Vulnerabilities
None known

GothAmazon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GothAmazon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
268
185 escaped
Nonce Checks
1
Capability Checks
4
File Operations
84
External Requests
4
Bundled Libraries
0

Output Escaping

41% escaped453 total outputs
Data Flows
7 unsanitized

Data Flow Analysis

8 flows7 with unsanitized paths
gothamazon_amp_redirect_handler (gothamzone.php:93)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
7 unprotected

GothAmazon Attack Surface

Entry Points16
Unprotected7

AJAX Handlers 6

authwp_ajax_kapsule_get_boutiquegotham_boutique.php:201
noprivwp_ajax_kapsule_get_boutiquegotham_boutique.php:202
authwp_ajax_kapsule_get_asingotham_spotlight_asin.php:48
noprivwp_ajax_kapsule_get_asingotham_spotlight_asin.php:49
authwp_ajax_kapsule_get_spotlightrandomgotham_spotlight_keyword.php:77
noprivwp_ajax_kapsule_get_spotlightrandomgotham_spotlight_keyword.php:78

REST API Routes 1

GET/wp-json/gtz/v1/smartimg/(?P<id>[a-zA-Z0-9+-_]+)gothamzone.php:2485

Shortcodes 9

[boutique] gotham_boutique.php:120
[inlineASIN] gotham_inline_asin.php:837
[inlinemonetizer] gotham_inline_text.php:765
[speedyshop] gotham_speedstore.php:114
[related_speedyshop] gotham_speedstore.php:229
[gothasin] gotham_spotlight_asin.php:37
[gothasin] gotham_spotlight_asin.php:945
[spotlightbyq] gotham_spotlight_keyword.php:46
[spotlightbyq] gotham_spotlight_keyword.php:1396
WordPress Hooks 28
actioninitgothamzone.php:72
filterquery_varsgothamzone.php:81
filterrobots_txtgothamzone.php:87
actiontemplate_redirectgothamzone.php:131
actionadmin_initgothamzone.php:144
actionwp_enqueue_scriptsgothamzone.php:412
actionwp_enqueue_scriptsgothamzone.php:1515
actionwp_enqueue_scriptsgothamzone.php:1532
filterautoptimize_filter_js_excludegothamzone.php:1541
filterrobots_txtgothamzone.php:1557
actionadmin_initgothamzone.php:1587
actionadmin_enqueue_scriptsgothamzone.php:1637
actionadmin_menugothamzone.php:1645
actionadmin_enqueue_scriptsgothamzone.php:1661
actionadmin_enqueue_scriptsgothamzone.php:1672
filtermce_external_pluginsgothamzone.php:1682
filtermce_buttonsgothamzone.php:1683
actionadmin_initgothamzone.php:1691
actionadmin_initgothamzone.php:1715
actionrest_api_initgothamzone.php:2484
actionwidgets_initgothamzone.php:2519
filtercomment_textgothamzone.php:2524
actionadd_meta_boxesgothamzone.php:2557
actionsave_postgothamzone.php:2585
actionwp_footergothamzone.php:2627
actionwp_footergothamzone.php:2643
filtercron_schedulesinc\erase_old_caching_files.php:18
actiongtz_suppression_mensuelle_fichiersinc\erase_old_caching_files.php:35

Scheduled Events 1

gtz_suppression_mensuelle_fichiers
Maintenance & Trust

GothAmazon Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 10, 2025
PHP min version7.4
Downloads10K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

GothAmazon Developer Profile

Kapsule Corp

7 plugins · 200 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
2 days
View full developer profile
Detection Fingerprints

How We Detect GothAmazon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gothamazon/css/gothamazon.css/wp-content/plugins/gothamazon/js/gothamazon.js
Script Paths
/wp-content/plugins/gothamazon/js/gothamazon.js
Version Parameters
gothamazon/css/gothamazon.css?ver=gothamazon/js/gothamazon.js?ver=

HTML / DOM Fingerprints

CSS Classes
gothamazon-container
HTML Comments
<!-- BEGIN GOTHAMAZON CODE --><!-- END GOTHAMAZON CODE -->
Data Attributes
data-gothamazon-product-iddata-gothamazon-asin
JS Globals
gothamazon_ajax_object
Shortcode Output
[gothamazon product_id=
FAQ

Frequently Asked Questions about GothAmazon