
Show Affiliate Disclosure Security & Risk Analysis
wordpress.org/plugins/show-affiliate-disclosureA customizable plugin to add affiliate disclosure text to your posts and pages, with multiple types and positions.
Is Show Affiliate Disclosure Safe to Use in 2026?
Generally Safe
Score 92/100Show Affiliate Disclosure has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "show-affiliate-disclosure" v1.0 plugin exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, proper escaping of all outputs, and the exclusive use of prepared statements for SQL queries are significant strengths. Furthermore, the plugin demonstrates an awareness of security by including capability checks, and the taint analysis revealed no critical or high-severity vulnerabilities. The vulnerability history also shows a clean record with no known CVEs, indicating a history of stable and secure development.
However, a notable area for concern is the complete absence of nonce checks across all entry points, which include three shortcodes. While the analysis reports zero unprotected entry points, the lack of nonce validation, especially on shortcodes which can be triggered by users or even automated processes, introduces a potential risk for Cross-Site Request Forgery (CSRF) attacks. Despite the limited attack surface and the presence of capability checks, the absence of nonce protection leaves a gap that could be exploited if an attacker can trick a logged-in user into triggering these shortcodes with malicious intent.
In conclusion, the plugin is built on a solid foundation with good coding practices in place, particularly regarding data sanitization and database interaction. The clean vulnerability history further bolsters confidence. The primary weakness identified is the oversight in implementing nonce checks, which is a common security best practice for handling user-initiated actions within WordPress. Addressing this would further harden the plugin's security.
Key Concerns
- Missing nonce checks on shortcodes
Show Affiliate Disclosure Security Vulnerabilities
Show Affiliate Disclosure Release Timeline
Show Affiliate Disclosure Code Analysis
Output Escaping
Data Flow Analysis
Show Affiliate Disclosure Attack Surface
Shortcodes 3
WordPress Hooks 2
Maintenance & Trust
Show Affiliate Disclosure Maintenance & Trust
Maintenance Signals
Community Trust
Show Affiliate Disclosure Alternatives
Affiliate Area Shortcodes by AffiliateWP
affiliatewp-affiliate-area-shortcodes
Customize your affiliate dashboard with 20+ powerful shortcodes. Show earnings, stats, referrals, and graphs anywhere on your site.
AffiliateWP – Leaderboard
affiliatewp-leaderboard
Display an affiliate leaderboard on your website
Disclaimify – Affiliate Disclosure / Disclaimer for WordPress
disclaimify
Disclaimify is the ultimate solution to add affiliate disclosure statements & inform your readers about affiliate links while ensuring transparency.
FMTC Affiliate Disclosure
fmtc-affiliate-disclosure
Add FTC-Compliant Disclosure statement to the beginning of your blog posts
WP Affiliate Disclosure
wp-affiliate-disclosure
Automatically add a customizable, FTC-compliant disclosure statement across your WordPress website based on the rule(s) you define.
Show Affiliate Disclosure Developer Profile
2 plugins · 0 total installs
How We Detect Show Affiliate Disclosure
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[affiliate_disclosure][sponsored_disclosure][partnership_disclosure]<p style="font-size: