Squirrel Links Security & Risk Analysis

wordpress.org/plugins/squirrel-links

Automatically convert product links into affiliate links across 3,000+ retailers. Monetize your WordPress blog without editing a single post.

0 active installs v1.0.3 PHP 7.4+ WP 5.8+ Updated Apr 14, 2026
affiliate-linksaffiliate-marketingautomatic-affiliatelink-managementmonetization
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Squirrel Links Safe to Use in 2026?

Generally Safe

Score 100/100

Squirrel Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The Squirrel Links plugin v1.0.3 demonstrates a strong security posture based on the provided static analysis and vulnerability history. The code appears to follow many security best practices, including the exclusive use of prepared statements for SQL queries and proper output escaping for all identified outputs. The absence of dangerous functions, file operations, and external HTTP requests (beyond the stated two, which lack details) further enhances its security. Crucially, there are no identified taint flows with unsanitized paths, indicating a low risk of code injection or data leakage.

The plugin's vulnerability history is pristine, with zero recorded CVEs of any severity. This suggests a consistent track record of secure development or a lack of past exploits targeting this specific plugin. The plugin's limited attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, also contributes significantly to its security by reducing the potential entry points for attackers.

In conclusion, Squirrel Links v1.0.3 presents a very low-risk profile. Its adherence to secure coding practices, clean vulnerability history, and minimal attack surface are commendable. The only potential areas for improvement would be understanding the nature of the two external HTTP requests, as their context could introduce minor risks if they interact with untrusted external services without proper validation. However, based on the data alone, the plugin is exceptionally secure.

Vulnerabilities
None known

Squirrel Links Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Squirrel Links Release Timeline

v1.0.3Current
v1.0.2
Code Analysis
Analyzed Apr 16, 2026

Squirrel Links Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
87 escaped
Nonce Checks
4
Capability Checks
5
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped87 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
handle_connect (admin/class-squirrel-admin.php:442)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Squirrel Links Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_menuadmin/class-squirrel-admin.php:19
actionadmin_enqueue_scriptsadmin/class-squirrel-admin.php:20
actionadmin_post_squirrel_registeradmin/class-squirrel-admin.php:21
actionadmin_post_squirrel_connectadmin/class-squirrel-admin.php:22
actionadmin_post_squirrel_disconnectadmin/class-squirrel-admin.php:23
actionadmin_post_squirrel_refresh_scriptadmin/class-squirrel-admin.php:24
actionadmin_noticesadmin/class-squirrel-admin.php:25
actionwp_enqueue_scriptsincludes/class-squirrel-script-injector.php:17
actionplugins_loadedsquirrel-links.php:70
Maintenance & Trust

Squirrel Links Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 14, 2026
PHP min version7.4
Downloads40

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Squirrel Links Developer Profile

obsidiansquirrel

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Squirrel Links

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/squirrel-links/assets/css/admin.css
Version Parameters
squirrel-links/assets/css/admin.css?ver=1.0.3

HTML / DOM Fingerprints

CSS Classes
squirrel-wrapsquirrel-headersquirrel-logosquirrel-taglinesquirrel-cardsquirrel-statussquirrel-status__dotsquirrel-status--connected+8 more
Data Attributes
data-form-iddata-modal-close
JS Globals
SquirrelLinks
FAQ

Frequently Asked Questions about Squirrel Links