Premium Link Cloaker Lite Security & Risk Analysis

wordpress.org/plugins/premium-link-cloaker-lite

Awesome yet easy-to-use link cloaker, designed for affiliate marketers. 100% newbie friendly.

10 active installs v1.0 PHP + WP 4.0+ Updated Oct 23, 2016
affiliatelink-cloakermarketing
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Premium Link Cloaker Lite Safe to Use in 2026?

Generally Safe

Score 85/100

Premium Link Cloaker Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "premium-link-cloaker-lite" plugin v1.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for the vast majority of its SQL queries (97%) and includes a reasonable number of nonce checks (8). Its vulnerability history is notably clean, with no recorded CVEs, suggesting a potentially stable and well-maintained codebase or limited previous exposure. The absence of external HTTP requests and file operations further reduces the attack surface in those areas.

However, significant concerns arise from the static analysis. A critical finding is that 100% of the analyzed taint flows (14 out of 14) have unsanitized paths, with 7 of these classified as high severity. This strongly indicates a risk of data being passed through the plugin without proper validation or sanitization, potentially leading to vulnerabilities like cross-site scripting (XSS) or path traversal if user-supplied input is involved. Furthermore, the output escaping is only properly implemented in 61% of cases, leaving a substantial portion of output vulnerable to unescaped data, which is a common vector for XSS attacks. The complete lack of capability checks for its entry points, although currently presenting zero known entry points, signifies a potential weakness if any new entry points are introduced or if the current structure is bypassed.

In conclusion, while the plugin's SQL query handling and the lack of a CVE history are strengths, the high number of unsanitized taint flows and the inadequate output escaping present significant security risks. These code-level issues, particularly the high-severity taint flows, demand immediate attention to prevent potential exploits, despite the absence of documented past vulnerabilities.

Key Concerns

  • High severity taint flows
  • Unsanitized paths in all flows
  • Insufficient output escaping
  • No capability checks
Vulnerabilities
None known

Premium Link Cloaker Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Premium Link Cloaker Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
31 prepared
Unescaped Output
52
81 escaped
Nonce Checks
8
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

97% prepared32 total queries

Output Escaping

61% escaped133 total outputs
Data Flows
14 unsanitized

Data Flow Analysis

14 flows14 with unsanitized paths
form_handler (includes\class-category.php:12)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Premium Link Cloaker Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_initincludes\admin\settings\class-settings.php:32
actionadmin_menuincludes\admin\settings\class-settings.php:33
actionadmin_enqueue_scriptsincludes\admin\settings\class-settings.php:34
filterstyle_loader_tagincludes\admin\settings\class-settings.php:35
filterscript_loader_tagincludes\admin\settings\class-settings.php:36
actionadmin_footerincludes\admin\settings\class-settings.php:37
actionadmin_initincludes\class-category.php:9
actioninitincludes\class-db.php:11
actioninitincludes\class-link.php:9
actionadmin_initincludes\class-link.php:10
actionplugins_loadedpremium-link-cloaker-lite.php:58
Maintenance & Trust

Premium Link Cloaker Lite Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedOct 23, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Premium Link Cloaker Lite Developer Profile

Yudhistira Mauris

5 plugins · 2K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Premium Link Cloaker Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/premium-link-cloaker-lite/assets/css/style-admin.min.css
Script Paths
/wp-content/plugins/premium-link-cloaker-lite/assets/js/script-admin.min.js
Version Parameters
premium-link-cloaker-lite/assets/css/style-admin.min.css?ver=premium-link-cloaker-lite/assets/js/script-admin.min.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-plcl-link-iddata-plcl-link-targetdata-plcl-link-clicksdata-plcl-link-categorydata-plcl-link-descriptiondata-plcl-link-created+1 more
JS Globals
PLCL_AJAX_URLPLCL_AJAX_NONCEPLCL_ADD_LINK_URLPLCL_LINK_EDIT_URLPLCL_LINK_CLICKS_URLPLCL_LINK_EDIT_ID+1 more
FAQ

Frequently Asked Questions about Premium Link Cloaker Lite