Guest Author Affiliate Security & Risk Analysis

wordpress.org/plugins/guest-author-affiliate

Allows your site's content authors to become your affiliates.

0 active installs v1.1.8 PHP 7.0+ WP 3.9+ Updated Jan 27, 2025
affiliateaffiliate-marketingaffiliate-pluginaffiliatesguest-author
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Guest Author Affiliate Safe to Use in 2026?

Generally Safe

Score 92/100

Guest Author Affiliate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The guest-author-affiliate plugin v1.1.8 exhibits a generally strong security posture, with no known historical vulnerabilities and a robust implementation of security best practices in its static analysis. The plugin demonstrates excellent adherence to secure coding by utilizing prepared statements for all SQL queries and implementing a healthy percentage of output escaping, minimizing the risk of common web vulnerabilities like SQL injection and cross-site scripting. Furthermore, the presence of nonce and capability checks on its entry points suggests a conscious effort to protect against unauthorized access and actions.

However, the analysis does reveal potential areas of concern. The presence of two AJAX handlers, while appearing to be protected by authentication checks based on the "Unprotected: 0" metric, warrants closer scrutiny. The taint analysis, while reporting no critical or high severity unsanitized paths, does indicate two flows with unsanitized paths. Though classified as likely lower severity due to the absence of critical issues, these warrant further investigation to ensure they don't lead to unforeseen vulnerabilities, especially in combination with other factors. The bundled Freemius library, while not explicitly flagged as outdated, represents a third-party component whose own security status should be periodically verified.

Overall, the plugin is well-developed from a security perspective, with a clean vulnerability history and proactive use of security features. The primary focus for improvement should be a thorough review of the two identified taint flows with unsanitized paths and verification of the security status of the bundled Freemius library to maintain its strong security standing.

Key Concerns

  • Taint flows with unsanitized paths detected
  • Bundled Freemius v1.0 library
Vulnerabilities
None known

Guest Author Affiliate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Guest Author Affiliate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
4
25 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared2 total queries

Output Escaping

86% escaped29 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
settings_page (includes\class-guest-author-affiliate-settings.php:400)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Guest Author Affiliate Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_guest_author_affiliate_set_affiliation_coockieincludes\class-guest-author-affiliate.php:147
noprivwp_ajax_guest_author_affiliate_set_affiliation_coockieincludes\class-guest-author-affiliate.php:148
WordPress Hooks 19
actionadmin_initguest-author-affiliate.php:31
actionadmin_noticesguest-author-affiliate.php:32
actionadmin_noticesguest-author-affiliate.php:90
actioninitincludes\class-guest-author-affiliate-settings.php:64
actionadmin_initincludes\class-guest-author-affiliate-settings.php:67
actionadmin_menuincludes\class-guest-author-affiliate-settings.php:70
actionwp_enqueue_scriptsincludes\class-guest-author-affiliate.php:123
actionwp_enqueue_scriptsincludes\class-guest-author-affiliate.php:124
actionadmin_enqueue_scriptsincludes\class-guest-author-affiliate.php:126
actionadmin_enqueue_scriptsincludes\class-guest-author-affiliate.php:132
actioninitincludes\class-guest-author-affiliate.php:144
actionloop_startincludes\class-guest-author-affiliate.php:146
filterguest_author_affiliate_get_affiliate_tokenincludes\class-guest-author-affiliate.php:151
actionguest_author_affiliate_set_affiliation_coockie_handlerincludes\class-guest-author-affiliate.php:157
filterguest_author_affiliate_get_affiliate_tokenincludes\class-guest-author-affiliate.php:165
actionguest_author_affiliate_set_affiliation_coockie_handlerincludes\class-guest-author-affiliate.php:171
filterwpam_woo_override_refkeyincludes\class-guest-author-affiliate.php:177
filterthe_contentincludes\class-guest-author-affiliate.php:340
actionloop_endincludes\class-guest-author-affiliate.php:341
Maintenance & Trust

Guest Author Affiliate Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 27, 2025
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Guest Author Affiliate Developer Profile

olegabr

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Guest Author Affiliate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/guest-author-affiliate/assets/css/guest-author-affiliate.css/wp-content/plugins/guest-author-affiliate/assets/js/guest-author-affiliate.js
Script Paths
/wp-content/plugins/guest-author-affiliate/assets/js/guest-author-affiliate.js
Version Parameters
guest-author-affiliate/assets/css/guest-author-affiliate.css?ver=guest-author-affiliate/assets/js/guest-author-affiliate.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-freemius-id="6455"
JS Globals
guest_author_affiliate_fs
FAQ

Frequently Asked Questions about Guest Author Affiliate