Tradebit Download and Affiliate Shop Security & Risk Analysis

wordpress.org/plugins/tradebit-download-shop

Tradebit is the leading platform to publish and sell digital goods like photos and music. This plugin integrates it into your Wordpress blog!

10 active installs v3.0.0 PHP + WP 2.7.0+ Updated Unknown
adminlinkswidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tradebit Download and Affiliate Shop Safe to Use in 2026?

Generally Safe

Score 100/100

Tradebit Download and Affiliate Shop has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "tradebit-download-shop" v3.0.0 plugin exhibits a mixed security posture. On the positive side, the absence of known vulnerabilities and a clean history of CVEs suggests a diligent maintenance effort or a lack of exploitation attempts. Furthermore, the absence of direct SQL queries without prepared statements and no external HTTP requests are strong indicators of good security practices in those areas.

However, significant concerns arise from the static analysis. The complete lack of output escaping across all identified outputs is a critical weakness, potentially leading to cross-site scripting (XSS) vulnerabilities if any user-supplied data is ever rendered directly. Additionally, the presence of unsanitized path flows in the taint analysis, even without critical or high severity flags, indicates a potential risk for directory traversal or file inclusion vulnerabilities, especially given the single file operation identified. The absence of nonce and capability checks across all entry points, while there are no entry points identified as unprotected, still presents a latent risk if new entry points are introduced or if the analysis missed subtle ways to trigger code execution.

In conclusion, while the plugin benefits from a clean vulnerability history and avoids some common pitfalls like raw SQL, the pervasive issue of unescaped output and the unsanitized path flows are serious security concerns that require immediate attention. The lack of authentication checks on any potential entry points further amplifies these risks.

Key Concerns

  • All outputs are unescaped
  • Unsanitized path flows found
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Tradebit Download and Affiliate Shop Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Tradebit Download and Affiliate Shop Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped11 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
tradebit_edit_settings (tradebit-shop.php:22)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Tradebit Download and Affiliate Shop Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menutradebit-shop.php:290
filtermedia_buttons_contexttradebit-shop.php:291
actionplugins_loadedtradebit-shop.php:294
Maintenance & Trust

Tradebit Download and Affiliate Shop Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedUnknown
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Tradebit Download and Affiliate Shop Developer Profile

tradebit

3 plugins · 30 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tradebit Download and Affiliate Shop

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
tradebit-pages
HTML Comments
$myopenurl : $mytbitresult
Data Attributes
name="tbitaction"name="tbitlogin"name="tbitpw"name="tbitpw2"name="tbitpayoutmail"name="tbitterms"+1 more
FAQ

Frequently Asked Questions about Tradebit Download and Affiliate Shop