Skimlinks Affiliate Marketing Tool Security & Risk Analysis

wordpress.org/plugins/skimlinks

Skimlinks is a content-to-commerce platform that helps publishers monetize outbound links to merchants.

900 active installs v1.3.1 PHP + WP 2.7.1+ Updated Jan 15, 2026
affiliatelinksmarketingmonetizationskimlinks
77
B · Generally Safe
CVEs total2
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is Skimlinks Affiliate Marketing Tool Safe to Use in 2026?

Mostly Safe

Score 77/100

Skimlinks Affiliate Marketing Tool is generally safe to use. 2 past CVEs were resolved. Keep it updated.

2 known CVEs 1 unpatched Last CVE: Sep 22, 2025Updated 2mo ago
Risk Assessment

The Skimlinks plugin v1.3.1 presents a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identifiable entry points like AJAX handlers, REST API routes, or shortcodes that lack authentication or permission checks. Additionally, all SQL queries are properly prepared, and there are no file operations, mitigating common vulnerability vectors. However, several concerning signals warrant attention. The presence of the `create_function` dangerous function is a significant red flag, as it can be exploited for code injection if not handled with extreme care, although no specific taint flows were detected in this analysis. Furthermore, the output escaping is only at 32%, suggesting a substantial risk of Cross-Site Scripting (XSS) vulnerabilities across various output contexts. The plugin also makes external HTTP requests, which could be a vector for Server-Side Request Forgery (SSRF) if not properly validated and sanitized.

The plugin's vulnerability history is particularly troubling, with two known CVEs, one of which remains unpatched. Both historical vulnerabilities are classified as medium severity and are related to Server-Side Request Forgery (SSRF) and Missing Authorization. This pattern indicates a recurring weakness in the plugin's handling of external interactions and access control. The fact that a vulnerability is still unpatched as of a future date (2025-09-22) is a critical concern, as it leaves users exposed to known exploits. While the current static analysis doesn't reveal exploitable taint flows or direct vulnerabilities, the combination of poor output escaping, the use of a dangerous function, and a history of SSRF and authorization issues, coupled with an unpatched CVE, paints a picture of a plugin that requires immediate attention and patching to mitigate significant risks.

Key Concerns

  • Unpatched CVE
  • Low output escaping percentage
  • Dangerous function used
  • External HTTP requests
  • No nonce checks
  • No capability checks
Vulnerabilities
2

Skimlinks Affiliate Marketing Tool Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-57943medium · 5.5Server-Side Request Forgery (SSRF)

Skimlinks Affiliate Marketing Tool <= 1.3 - Authenticated (Administrator+) Server-Side Request Forgery

Sep 22, 2025Unpatched
CVE-2025-57944medium · 6.5Missing Authorization

Skimlinks Affiliate Marketing Tool <= 1.3 - Missing Authorization

Sep 22, 2025 Patched in 1.3.1 (158d)
Code Analysis
Analyzed Mar 16, 2026

Skimlinks Affiliate Marketing Tool Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
25
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('widgets_init', create_function('', 'return register_widget("sl_disclosure_widget");'));widget.php:102

Output Escaping

32% escaped37 total outputs
Attack Surface

Skimlinks Affiliate Marketing Tool Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionadmin_menuadmin.php:5
actionadmin_initadmin.php:6
actionadmin_initadmin.php:7
actionadmin_initadmin.php:8
actionadmin_print_scripts-settings_page_skimlinks-optionsadmin.php:43
actionupdate_option_sl_publisher_idadmin.php:113
actionupdate_option_sl_subdomainadmin.php:118
actionadd_option_sl_publisher_idadmin.php:123
actionadd_option_sl_subdomainadmin.php:128
actionadmin_noticesadmin.php:389
actionwp_footerhooks.php:4
actionswitch_themehooks.php:7
actiontemplate_redirecthooks.php:10
filterthe_contenthooks.php:18
filterthe_content_rsshooks.php:20
filterthe_content_feedhooks.php:21
filterthe_contenthooks.php:28
actionwidgets_initwidget.php:102
Maintenance & Trust

Skimlinks Affiliate Marketing Tool Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 15, 2026
PHP min version
Downloads57K

Community Trust

Rating64/100
Number of ratings6
Active installs900
Developer Profile

Skimlinks Affiliate Marketing Tool Developer Profile

Skimlinks

1 plugin · 900 total installs

63
trust score
Avg Security Score
77/100
Avg Patch Time
158 days
View full developer profile
Detection Fingerprints

How We Detect Skimlinks Affiliate Marketing Tool

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/skimlinks/assets/skimlinks.js
Script Paths
/assets/skimlinks.js

HTML / DOM Fingerprints

CSS Classes
sl_messages
JS Globals
SL_PLUGIN_URL
FAQ

Frequently Asked Questions about Skimlinks Affiliate Marketing Tool