Wink Affiliate WordPress Plugin Security & Risk Analysis

wordpress.org/plugins/wink2travel

Integrates WordPress with your Wink account. Learn more at https://studio.wink.travel.

0 active installs v1.4.20 PHP 7.4+ WP 4.7+ Updated Sep 7, 2024
affiliate-networkbookinghoteltravelwink2travel
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Wink Affiliate WordPress Plugin Safe to Use in 2026?

Generally Safe

Score 92/100

Wink Affiliate WordPress Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The wink2travel plugin v1.4.20 demonstrates a strong security posture in several key areas. The static analysis shows a complete absence of exploitable entry points like AJAX handlers, REST API routes, shortcodes, and cron events that are not protected. Furthermore, the plugin avoids dangerous functions and makes no file operations. Notably, all SQL queries are properly prepared, and there are no recorded vulnerabilities or CVEs, indicating a history of stable and secure development. The presence of capability checks and the proper escaping of a significant portion of output (68%) are also positive signs.

However, there are areas that warrant attention. The plugin makes external HTTP requests, which, while not inherently a vulnerability, can become a risk if the target endpoint is compromised or if the data transmitted is not handled securely. The complete lack of nonce checks is a significant concern, especially since there are no AJAX handlers or REST API routes to protect. While the attack surface for these specific entry points is currently zero, if future updates introduce such features without proper nonce protection, it could lead to Cross-Site Request Forgery (CSRF) vulnerabilities. The taint analysis showing zero flows with unsanitized paths is reassuring, but this is based on a limited analysis (0 flows analyzed).

In conclusion, wink2travel v1.4.20 is largely secure, with excellent practices regarding SQL, lack of historical vulnerabilities, and a well-defined, protected attack surface. The primary concerns revolve around potential future risks from external HTTP requests and the complete absence of nonce checks, which, although not currently exploitable due to the lack of specific entry points, represents a potential oversight for future development. The plugin's strengths significantly outweigh its weaknesses, but vigilance regarding the identified potential risks is advised.

Key Concerns

  • No nonce checks detected
  • External HTTP requests made
  • 68% of output escaping
Vulnerabilities
None known

Wink Affiliate WordPress Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Wink Affiliate WordPress Plugin Release Timeline

v1.4.20Current
v1.4.19
v1.4.18
v1.4.16
v1.4.15
v1.4.14
v1.4.13
v1.4.12
v1.4.11
Code Analysis
Analyzed Apr 6, 2026

Wink Affiliate WordPress Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
19 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

68% escaped28 total outputs
Attack Surface

Wink Affiliate WordPress Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 28
actionwp_footerincludes/elementHandler.php:18
actioninitincludes/elements/avada/fusionElements.php:6
actionfusion_builder_before_initincludes/elements/avada/fusionElements.php:10
actioninitincludes/elements/elementor/elementorWidgets.php:6
actionelementor/controls/controls_registeredincludes/elements/elementor/elementorWidgets.php:8
actionelementor/widgets/widgets_registeredincludes/elements/elementor/elementorWidgets.php:19
actioninitincludes/elements/winkaccount.php:9
filterwinkShortcodesincludes/elements/winkaccount.php:11
actioninitincludes/elements/winkcontent.php:23
filterwinkShortcodesincludes/elements/winkcontent.php:25
actioninitincludes/elements/winkitinerary.php:9
filterwinkShortcodesincludes/elements/winkitinerary.php:11
actioninitincludes/elements/winkitineraryform.php:9
filterwinkShortcodesincludes/elements/winkitineraryform.php:11
actioninitincludes/elements/winklookup.php:9
filterwinkShortcodesincludes/elements/winklookup.php:11
actioninitincludes/elements/winksearch.php:9
filterwinkShortcodesincludes/elements/winksearch.php:11
actioninitincludes/elements/wpbakery/vcElements.php:6
actionvc_before_initincludes/elements/wpbakery/vcElements.php:11
actionvc_before_initincludes/elements/wpbakery/vcElements.php:12
actioncustomize_registerwink.php:36
actionadmin_noticeswink.php:37
filterblock_categories_allwink.php:39
actionwp_enqueue_scriptswink.php:41
filterscript_loader_tagwink.php:43
actionadmin_enqueue_scriptswink.php:44
actioncustomize_save_afterwink.php:48
Maintenance & Trust

Wink Affiliate WordPress Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedSep 7, 2024
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Wink Affiliate WordPress Plugin Developer Profile

bjornharvold

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wink Affiliate WordPress Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wink2travel/css/customize.css/wp-content/plugins/wink2travel/img/logo.png
Script Paths
/wp-content/plugins/wink2travel/js/elements.js
Version Parameters
wink2travel/css/customize.css?ver=wink2travel/js/elements.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-cfasync="true"
JS Globals
winkCore
Shortcode Output
[wink]
FAQ

Frequently Asked Questions about Wink Affiliate WordPress Plugin