Cloak Affiliate Links for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woocommerce-cloak-affiliate-links

Cloak your WooCommerce external & affiliate links.

2K active installs v1.0.37 PHP + WP 4.7.0+ Updated Sep 15, 2025
affiliate-linkscloakexternalmaskredirect
98
A · Safe
CVEs total2
Unpatched0
Last CVEJan 24, 2025
Safety Verdict

Is Cloak Affiliate Links for WooCommerce Safe to Use in 2026?

Generally Safe

Score 98/100

Cloak Affiliate Links for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jan 24, 2025Updated 6mo ago
Risk Assessment

The "woocommerce-cloak-affiliate-links" plugin, version 1.0.37, exhibits a generally good security posture with a very limited attack surface. The absence of unprotected AJAX handlers, REST API routes, shortcodes, and cron events is commendable. Furthermore, the code analysis reveals no dangerous functions, no raw SQL queries (all prepared statements), and no external HTTP requests, which are all positive indicators. The presence of nonce and capability checks, along with proper output escaping for most outputs, demonstrates adherence to secure coding practices. Taint analysis also shows no identified critical or high-severity vulnerabilities. However, the plugin's vulnerability history presents a significant concern. Two known CVEs have been documented, with one high and one medium severity vulnerability previously identified. Although currently unpatched vulnerabilities are zero, the pattern of past Cross-Site Request Forgery (CSRF) and Improper Access Control issues suggests a need for continued vigilance. The last vulnerability recorded in 2025 indicates that recent security reviews might have identified issues, even if they have since been patched. The plugin's strengths lie in its robust internal security measures and minimal attack vectors, but its historical vulnerability record necessitates a cautious approach and assurance of ongoing security maintenance.

Key Concerns

  • Past High Severity Vulnerability
  • Past Medium Severity Vulnerability
  • Past CSRF and Improper Access Control Vulnerabilities
  • Some output not properly escaped
Vulnerabilities
2

Cloak Affiliate Links for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2025-24647medium · 4.3Cross-Site Request Forgery (CSRF)

WooCommerce Cloak Affiliate Links <= 1.0.35 - Cross-Site Request Forgery

Jan 24, 2025 Patched in 1.0.36 (5d)
CVE-2024-1308high · 7.5Improper Access Control

WooCommerce Cloak Affiliate Links <= 1.0.33 - Missing Authorization to Unauthenticated Permalink Modification

Mar 20, 2024 Patched in 1.0.34 (134d)
Code Analysis
Analyzed Mar 16, 2026

Cloak Affiliate Links for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
4 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped6 total outputs
Attack Surface

Cloak Affiliate Links for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionbefore_woocommerce_initwoocommerce-cloak-affiliate-links.php:53
filterquery_varswoocommerce-cloak-affiliate-links.php:78
filterrewrite_rules_arraywoocommerce-cloak-affiliate-links.php:79
filterwoocommerce_product_classwoocommerce-cloak-affiliate-links.php:80
filterrobots_txtwoocommerce-cloak-affiliate-links.php:81
actiontemplate_redirectwoocommerce-cloak-affiliate-links.php:84
actionplugins_loadedwoocommerce-cloak-affiliate-links.php:85
actionadmin_initwoocommerce-cloak-affiliate-links.php:86
actionadmin_initwoocommerce-cloak-affiliate-links.php:87
actionadmin_menuwoocommerce-cloak-affiliate-links.php:88
actionadmin_initwoocommerce-cloak-affiliate-links.php:89
actionwccal_clickthroughwoocommerce-cloak-affiliate-links.php:90
Maintenance & Trust

Cloak Affiliate Links for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedSep 15, 2025
PHP min version
Downloads53K

Community Trust

Rating86/100
Number of ratings12
Active installs2K
Developer Profile

Cloak Affiliate Links for WooCommerce Developer Profile

datafeedr

6 plugins · 23K total installs

83
trust score
Avg Security Score
93/100
Avg Patch Time
70 days
View full developer profile
Detection Fingerprints

How We Detect Cloak Affiliate Links for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-cloak-affiliate-links/css/wccal-admin.css/wp-content/plugins/woocommerce-cloak-affiliate-links/js/wccal-admin.js
Script Paths
/wp-content/plugins/woocommerce-cloak-affiliate-links/js/wccal-admin.js

HTML / DOM Fingerprints

CSS Classes
wccal_options
Data Attributes
name="wccal_options[status]"name="wccal_options[robots]"
FAQ

Frequently Asked Questions about Cloak Affiliate Links for WooCommerce