
WP Affiliate Card Security & Risk Analysis
wordpress.org/plugins/wp-affiliate-cardWP Affiliate Card
Is WP Affiliate Card Safe to Use in 2026?
Generally Safe
Score 85/100WP Affiliate Card has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-affiliate-card" plugin v0.1 demonstrates a generally good security posture with a very small attack surface and no recorded vulnerabilities. The static analysis shows no AJAX handlers, REST API routes, shortcodes, or cron events, which are common entry points for exploitation. Furthermore, the code reports zero dangerous functions, no raw SQL queries (all prepared statements), and no file operations or external HTTP requests, all positive indicators. The presence of one nonce check and the absence of capability checks might suggest a very basic or limited functionality that doesn't require complex authorization, or it could be a missed security control.
However, a significant concern is the complete lack of output escaping. With two outputs analyzed and 0% properly escaped, this presents a considerable risk for Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the frontend without proper escaping is vulnerable to malicious script injection. While the taint analysis found no unsanitized paths, the lack of output escaping means that even if data is sanitized for input, it could still be rendered in a way that allows for XSS if not escaped on output.
The plugin's vulnerability history is clean, with zero known CVEs. This, combined with the absence of critical taint flows and dangerous functions, is reassuring. However, the critical weakness in output escaping cannot be overlooked. The plugin's strengths lie in its limited attack surface and secure handling of database queries and external interactions. Its primary weakness is the severe lack of output escaping, which needs immediate attention to mitigate XSS risks.
Key Concerns
- 0% output escaping on 2 outputs
WP Affiliate Card Security Vulnerabilities
WP Affiliate Card Release Timeline
WP Affiliate Card Code Analysis
Output Escaping
Data Flow Analysis
WP Affiliate Card Attack Surface
WordPress Hooks 5
Maintenance & Trust
WP Affiliate Card Maintenance & Trust
Maintenance Signals
Community Trust
WP Affiliate Card Alternatives
WP Associate Post R2
wp-associate-post-r2
Affiliate easy installation plugin. Contributing to the monetization of your blog.
EC Links
ec-links
Amazonや楽天市場、Yahoo!ショッピングのアフィリエイトリンクを綺麗にかんたんにまとめて表示できるカスタムブロックを追加。ASPで取得したアフィリエイトリンクをそのまま貼り付けるだけで、綺麗なボタンのリンクが作れます。
Advanced Ads – Ad Manager & AdSense
advanced-ads
The only complete toolkit for all ad types. Grow your revenue with AdSense, Amazon—or any affiliate network. Get pinpoint targeting and best support!
ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin
thirstyaffiliates
🔗 Affiliate link management & cloaker tool. Easily manage, shrink and track your affiliate links in WordPress. 🔥
AffiliateX – Amazon Affiliate Plugin
affiliatex
AffiliateX is the best WordPress Amazon Affiliate Plugin. Create professional affiliate websites with customizable WordPress Amazon Affiliate Blocks.
WP Affiliate Card Developer Profile
1 plugin · 0 total installs
How We Detect WP Affiliate Card
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-affiliate-card/style-admin.css/wp-content/plugins/wp-affiliate-card/style-visitor.css/wp-content/plugins/wp-affiliate-card/block.jsHTML / DOM Fingerprints
aficard-url_amazonaficard-url_rakutenaficard-url_yahooaficard-url_yodobashiall_open