Sovrn Security & Risk Analysis

wordpress.org/plugins/viglink

Maximize your affiliate revenue with Sovrn Commerce - link optimization, price comparisons, and unified reporting.

1K active installs v1.0.7 PHP + WP 2.7+ Updated Oct 28, 2025
affiliateaffiliate-marketingecommercelink-trackingmonetization
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Sovrn Safe to Use in 2026?

Generally Safe

Score 100/100

Sovrn has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The static analysis of the "viglink" v1.0.7 plugin reveals a remarkably clean codebase with no identified vulnerabilities in the attack surface, code signals, or taint analysis. The plugin demonstrates strong adherence to security best practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no file operations or external HTTP requests. The absence of identified vulnerabilities in its history, combined with the lack of critical or high-severity issues, further contributes to a positive security posture. However, the fact that 100% of its limited output functions are not properly escaped presents a notable weakness. While the plugin's attack surface is currently zero, this lack of output escaping could become a significant risk if any entry points were to be introduced or if the plugin's functionality changes in future updates without addressing this.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Sovrn Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sovrn Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Sovrn Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actiontemplate_redirectviglink.php:263
filterthe_contentviglink.php:270
filterthe_content_rssviglink.php:273
filterthe_content_feedviglink.php:274
actionadmin_initviglink.php:282
actionadmin_menuviglink.php:284
actionwp_footerviglink.php:288
Maintenance & Trust

Sovrn Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 28, 2025
PHP min version
Downloads110K

Community Trust

Rating60/100
Number of ratings8
Active installs1K
Developer Profile

Sovrn Developer Profile

Sovrn

1 plugin · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sovrn

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/viglink/viglink.css/wp-content/plugins/viglink/viglink.js
Script Paths
//cdn.viglink.com/api/vglnk.js
Version Parameters
viglink/viglink.css?ver=viglink/viglink.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Sovrn: https://www.sovrn.com --><!-- end Sovrn -->
Data Attributes
id="viglink-key"id="viglink-enable-rss-rewrites"
JS Globals
vglnk
FAQ

Frequently Asked Questions about Sovrn