
MWW Disclaimer Buttons Security & Risk Analysis
wordpress.org/plugins/mww-disclaimer-buttonsThe FTC requires that you put disclosures at the top of your post if you were compensated in any way (affiliate links, free products, or payment).
Is MWW Disclaimer Buttons Safe to Use in 2026?
Generally Safe
Score 98/100MWW Disclaimer Buttons has a strong security track record. Known vulnerabilities have been patched promptly.
The mww-disclaimer-buttons v3.5 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. The code also demonstrates good practices by exclusively using prepared statements for SQL queries, performing nonce and capability checks, and not making external HTTP requests or file operations. However, a significant concern arises from the output escaping, where only 53% of outputs are properly escaped, leaving a substantial portion potentially vulnerable to Cross-Site Scripting (XSS) attacks. The plugin's vulnerability history is also a notable weakness, with two previously discovered medium-severity CVEs, both related to Cross-Site Scripting. While there are currently no unpatched vulnerabilities, the recurring pattern of XSS issues indicates a persistent challenge in sanitizing user-supplied data before it's rendered on the frontend. The absence of taint analysis data is a limitation, preventing a deeper understanding of potential data flow vulnerabilities. Overall, while the plugin has a small attack surface and employs some good security practices, the inadequate output escaping and past XSS vulnerabilities require careful consideration and ongoing vigilance.
Key Concerns
- Inadequate output escaping (47% not escaped)
- History of medium severity XSS vulnerabilities
MWW Disclaimer Buttons Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
MWW Disclaimer Buttons <= 3.41 - Authenticated (Administrator+) Stored Cross-Site Scripting
MWW Disclaimer Buttons <= 3.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
MWW Disclaimer Buttons Code Analysis
Output Escaping
MWW Disclaimer Buttons Attack Surface
WordPress Hooks 8
Maintenance & Trust
MWW Disclaimer Buttons Maintenance & Trust
Maintenance Signals
Community Trust
MWW Disclaimer Buttons Alternatives
fley Sponsored Posts
fley-sponsored-posts
Just install fley Sponsored Posts to add a sponsored post Info above your posts or pages.
PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin
pretty-link
🌠 The best WordPress link management, branding, tracking, sharing and payments plugin. Easily make pretty & trackable shortlinks. 🔗
ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin
thirstyaffiliates
🔗 Affiliate link management & cloaker tool. Easily manage, shrink and track your affiliate links in WordPress. 🔥
BetterLinks – URL Shortener, Link Tracking, Analytics & Affiliate Link Manager
betterlinks
Ultimate plugin to create, shorten, track and manage any URL. Gather analytics reports and run successful marketing campaigns easily.
Content Egg – Affiliate Product Importer & Price Comparison
content-egg
Import affiliate products, compare prices, sync to WooCommerce, and auto-generate SEO content with AI — all in one toolkit.
MWW Disclaimer Buttons Developer Profile
2 plugins · 61K total installs
How We Detect MWW Disclaimer Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mww-disclaimer-buttons/buttons.cssmww-disclaimer-buttons/buttons.css?ver=HTML / DOM Fingerprints
disclaimer-buttondisclaimer-buttonsname="disc-affiliate"name="disc-pr"name="disc-sponsored"name="mww_disclaimer_nonce"name="mwwd_settings[disclaimerpageID]"name="mwwd_settings[buttonBG]"+8 more<a href="" class="disclaimer-button">Sponsored</a> " class="disclaimer-button">Affiliate Links</a> " class="disclaimer-button">PR Sample</a>