
Cloak Affiliate Links for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woocommerce-cloak-affiliate-linksCloak your WooCommerce external & affiliate links.
Is Cloak Affiliate Links for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100Cloak Affiliate Links for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "woocommerce-cloak-affiliate-links" plugin, version 1.0.37, exhibits a generally good security posture with a very limited attack surface. The absence of unprotected AJAX handlers, REST API routes, shortcodes, and cron events is commendable. Furthermore, the code analysis reveals no dangerous functions, no raw SQL queries (all prepared statements), and no external HTTP requests, which are all positive indicators. The presence of nonce and capability checks, along with proper output escaping for most outputs, demonstrates adherence to secure coding practices. Taint analysis also shows no identified critical or high-severity vulnerabilities. However, the plugin's vulnerability history presents a significant concern. Two known CVEs have been documented, with one high and one medium severity vulnerability previously identified. Although currently unpatched vulnerabilities are zero, the pattern of past Cross-Site Request Forgery (CSRF) and Improper Access Control issues suggests a need for continued vigilance. The last vulnerability recorded in 2025 indicates that recent security reviews might have identified issues, even if they have since been patched. The plugin's strengths lie in its robust internal security measures and minimal attack vectors, but its historical vulnerability record necessitates a cautious approach and assurance of ongoing security maintenance.
Key Concerns
- Past High Severity Vulnerability
- Past Medium Severity Vulnerability
- Past CSRF and Improper Access Control Vulnerabilities
- Some output not properly escaped
Cloak Affiliate Links for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WooCommerce Cloak Affiliate Links <= 1.0.35 - Cross-Site Request Forgery
WooCommerce Cloak Affiliate Links <= 1.0.33 - Missing Authorization to Unauthenticated Permalink Modification
Cloak Affiliate Links for WooCommerce Code Analysis
Output Escaping
Cloak Affiliate Links for WooCommerce Attack Surface
WordPress Hooks 12
Maintenance & Trust
Cloak Affiliate Links for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Cloak Affiliate Links for WooCommerce Alternatives
BetterLinks – URL Shortener, Link Tracking, Analytics & Affiliate Link Manager
betterlinks
Ultimate plugin to create, shorten, track and manage any URL. Gather analytics reports and run successful marketing campaigns easily.
Affiliate Links – Link Cloaking and Management
affiliate-links
Create any redirect links to any website from your WordPress Admin. Perfect for the affiliate links masking.
CleanLinks
cleanlinks
Create branded short links, manage redirects, cloak affiliate URLs, and export links via CSV – all from your WordPress dashboard.
Page Links To
page-links-to
Lets you make a WordPress page (or port or other content type) link to a URL of your choosing (on your site, or on another site), instead of its norma …
ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin
thirstyaffiliates
🔗 Affiliate link management & cloaker tool. Easily manage, shrink and track your affiliate links in WordPress. 🔥
Cloak Affiliate Links for WooCommerce Developer Profile
6 plugins · 23K total installs
How We Detect Cloak Affiliate Links for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woocommerce-cloak-affiliate-links/css/wccal-admin.css/wp-content/plugins/woocommerce-cloak-affiliate-links/js/wccal-admin.js/wp-content/plugins/woocommerce-cloak-affiliate-links/js/wccal-admin.jsHTML / DOM Fingerprints
wccal_optionsname="wccal_options[status]"name="wccal_options[robots]"