
MyDirtyHobby Affiliates Security & Risk Analysis
wordpress.org/plugins/mydirtyhobby-affiliate-sign-upMyDirtyHobby Affiliate Plugin
Is MyDirtyHobby Affiliates Safe to Use in 2026?
Generally Safe
Score 85/100MyDirtyHobby Affiliates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mydirtyhobby-affiliate-sign-up" plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no known vulnerabilities or CVEs. The absence of file operations, external HTTP requests, and bundled libraries further reduces potential attack vectors.
However, the static analysis reveals significant areas for concern. The plugin has a lack of nonce checks and capability checks, which are critical for preventing CSRF attacks and ensuring proper authorization. Furthermore, only 15% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the current attack surface is small and there are no unprotected entry points directly observed in the static analysis, the lack of essential security controls on the single shortcode entry point is a major weakness. The absence of taint analysis flows is not necessarily a sign of security but could also indicate the analysis tool's limitations or a lack of complex data manipulation within the plugin.
In conclusion, despite a clean vulnerability history and the avoidance of common risky coding patterns like raw SQL, the plugin's security is severely undermined by the apparent absence of nonce and capability checks, coupled with a high rate of unescaped output. These issues create a substantial risk of XSS and potentially other client-side attacks, which could be exploited through the shortcode's execution.
Key Concerns
- Missing nonce checks
- Missing capability checks
- High rate of unescaped output
MyDirtyHobby Affiliates Security Vulnerabilities
MyDirtyHobby Affiliates Release Timeline
MyDirtyHobby Affiliates Code Analysis
Output Escaping
MyDirtyHobby Affiliates Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
MyDirtyHobby Affiliates Maintenance & Trust
Maintenance Signals
Community Trust
MyDirtyHobby Affiliates Alternatives
PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin
pretty-link
🌠 The best WordPress link management, branding, tracking, sharing and payments plugin. Easily make pretty & trackable shortlinks. 🔗
Advanced Ads – Ad Manager & AdSense
advanced-ads
The only complete toolkit for all ad types. Grow your revenue with AdSense, Amazon—or any affiliate network. Get pinpoint targeting and best support!
Age Gate
age-gate
A plugin to check the age of a visitor before view site or specified content
ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin
thirstyaffiliates
🔗 Affiliate link management & cloaker tool. Easily manage, shrink and track your affiliate links in WordPress. 🔥
AdRotate Banner Manager
adrotate
Easily manage, and schedule ads on your WordPress site with AdRotate. Support for Google AdSense, Amazon, and custom banners. Start monetizing today!
MyDirtyHobby Affiliates Developer Profile
1 plugin · 200 total installs
How We Detect MyDirtyHobby Affiliates
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mydirtyhobby-affiliate-sign-up/admin/css/mdh-promote-admin.css/wp-content/plugins/mydirtyhobby-affiliate-sign-up/admin/js/mdh-promote-admin.js/wp-content/plugins/mydirtyhobby-affiliate-sign-up/admin/js/mdh-promote-admin.jsmydirtyhobby-affiliate-sign-up/admin/css/mdh-promote-admin.css?ver=mydirtyhobby-affiliate-sign-up/admin/js/mdh-promote-admin.js?ver=