
i2 AZON Security & Risk Analysis
wordpress.org/plugins/i2-azonThis plugin allow you to add affiliate links, amazon product box and images from amazon using advertising api or with out api using chrome extention.
Is i2 AZON Safe to Use in 2026?
Generally Safe
Score 85/100i2 AZON has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The i2-azon plugin v0.2.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for the vast majority of its SQL queries and has no recorded vulnerability history, suggesting a potentially stable and well-maintained codebase. However, significant concerns arise from its attack surface. A substantial portion of its entry points, specifically all 7 REST API routes, lack permission callbacks, making them vulnerable to unauthorized access and potential manipulation. Furthermore, the absence of nonce checks on its AJAX handlers, although there are none, and the presence of only 2 capability checks overall indicate a reliance on other security mechanisms that might not be sufficient on their own. The output escaping is also not entirely robust, with 29% of outputs potentially unescaped, which could lead to cross-site scripting vulnerabilities if user-supplied data is not handled carefully.
While the static analysis did not reveal any dangerous functions or critical taint flows, the large number of unprotected REST API routes is a significant security risk. This could allow unauthenticated users to interact with sensitive plugin functionality, potentially leading to data exposure or modification. The lack of nonce checks on AJAX is a concern if any AJAX functionality is ever added, and the moderate percentage of unescaped output warrants attention. The plugin's clean vulnerability history is a positive indicator, but it should not detract from addressing the identified weaknesses in its current implementation. Overall, the plugin has some strong security foundations, but the unprotected attack surface and less than perfect output escaping represent notable risks that should be mitigated.
Key Concerns
- Unprotected REST API routes
- Low number of capability checks
- Unescaped output
i2 AZON Security Vulnerabilities
i2 AZON Code Analysis
SQL Query Safety
Output Escaping
i2 AZON Attack Surface
REST API Routes 7
Shortcodes 1
WordPress Hooks 21
Maintenance & Trust
i2 AZON Maintenance & Trust
Maintenance Signals
Community Trust
i2 AZON Alternatives
AmaSync – Amazon Product Importer & Affiliate for WooCommerce
affiliate-products-importer-for-woocommerce
Easily import Amazon affiliate products into your WooCommerce store.
ProductLinker for Amazon
productlinker-for-amazon
Create affiliate product lists using just ASINs — no Amazon API key required. Perfect for bloggers who can't qualify for or don't want API access.
Simple Emzon Links
simple-emzon-links
Simple Emzon Links is a simple WordPress plugin that allow you to create Amazon affiliate links within your WordPress post editor with price and image …
Amazon Product in a Post Plugin
amazon-product-in-a-post-plugin
Add formatted Amazon Products to any page or post using the Amazon Product Advertising API.
Add & Replace Affiliate Links for Amazon
add-replace-affiliate-links-for-amazon
Add & Replace Affiliate Links for Amazon plugin helps you to add or update Amazon Associate tag parameters in links.
i2 AZON Developer Profile
1 plugin · 50 total installs
How We Detect i2 AZON
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/i2-azon/dist/css/style.css/wp-content/plugins/i2-azon/dist/js/admin.js/wp-content/plugins/i2-azon/dist/js/admin.jsi2-azon/dist/css/style.css?ver=i2-azon/dist/js/admin.js?ver=HTML / DOM Fingerprints
i2_azon_setting_pagei2-azon-setting-tabid="i2_azon_setting_page"id="i2-azon-setting-tab"id="tab-amazon"id="tab-activation"I2_AZON_PLUGIN_NAMEI2_AZON_VERI2_AZON_DEBUGI2_AZON_BASE_FILEI2_AZON_ROOTI2_AZON_DIR_PATH+1 more