Viet Nam Affiliate Security & Risk Analysis

wordpress.org/plugins/viet-nam-affiliate

Việt Nam affiliate tools là công cụ cho phép bạn chuyển đổi các link trên post của bạn thành link affiliate hỗ trợ tracking chi tiết, đầy đủ.

10 active installs v1.0.0 PHP 5.5+ WP 2.0+ Updated Apr 24, 2019
affiliateaffiliate-toolsmmoviet-nam-affiliate
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEMay 6, 2024
Safety Verdict

Is Viet Nam Affiliate Safe to Use in 2026?

Use With Caution

Score 64/100

Viet Nam Affiliate has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: May 6, 2024Updated 6yr ago
Risk Assessment

The "viet-nam-affiliate" plugin v1.0.0 exhibits a concerning security posture despite a seemingly small attack surface. While there are no reported AJAX handlers, REST API routes, shortcodes, or cron events, the static analysis reveals significant weaknesses. Notably, 50% of SQL queries are not using prepared statements, presenting a risk of SQL injection. Furthermore, a critical issue is the complete lack of output escaping, meaning all data outputted by the plugin is potentially vulnerable to Cross-Site Scripting (XSS) attacks. The taint analysis confirms this, with 100% of analyzed flows having unsanitized paths and two flows identified as high severity.

The plugin's vulnerability history is also a major red flag. It has one known, currently unpatched medium-severity CVE, which is a common cross-site scripting vulnerability. This pattern, combined with the static analysis findings, strongly suggests a history of insecure coding practices, particularly around input handling and output sanitization. The outdated bundled library, DataTables v1.10.18, could also introduce additional vulnerabilities if it has known exploits. In conclusion, while the attack surface appears minimal, the lack of input validation, unescaped output, and the unpatched CVE indicate a significant and active security risk that requires immediate attention.

Key Concerns

  • Unpatched CVE
  • High severity taint flows
  • No output escaping
  • Raw SQL queries
  • Bundled outdated library
Vulnerabilities
1

Viet Nam Affiliate Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-34417medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Viet Nam Affiliate <= 1.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

May 6, 2024Unpatched
Code Analysis
Analyzed Mar 17, 2026

Viet Nam Affiliate Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
2 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables1.10.18

SQL Query Safety

50% prepared4 total queries

Output Escaping

0% escaped4 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
checkRedirect (core\TDC.php:44)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Viet Nam Affiliate Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filtertemplate_redirectviet-nam-affiliate.php:56
actionadmin_enqueue_scriptsviet-nam-affiliate.php:117
actionadmin_menuviet-nam-affiliate.php:118
filterthe_contentviet-nam-affiliate.php:119
actioninitviet-nam-affiliate.php:120
Maintenance & Trust

Viet Nam Affiliate Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedApr 24, 2019
PHP min version5.5
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Viet Nam Affiliate Developer Profile

thanhtaivtt

1 plugin · 10 total installs

69
trust score
Avg Security Score
64/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Viet Nam Affiliate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/viet-nam-affiliate/assets/css/datatables.min.css/wp-content/plugins/viet-nam-affiliate/assets/js/datatables.min.js/wp-content/plugins/viet-nam-affiliate/assets/js/init.js
Script Paths
/wp-content/plugins/viet-nam-affiliate/assets/js/datatables.min.js/wp-content/plugins/viet-nam-affiliate/assets/js/init.js

HTML / DOM Fingerprints

HTML Comments
<!-- VIET NAM Affiliate --><!-- @link https://toidicode.com --><!-- @since 1.0.0 --><!-- @package Toidicode.com -->+16 more
FAQ

Frequently Asked Questions about Viet Nam Affiliate