WP Associate Post R2 Security & Risk Analysis

wordpress.org/plugins/wp-associate-post-r2

Affiliate easy installation plugin. Contributing to the monetization of your blog.

3K active installs v5.0.1 PHP 7.3+ WP 5.8+ Updated Sep 16, 2025
affiliateamazonmediarakutenyahoo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Associate Post R2 Safe to Use in 2026?

Generally Safe

Score 100/100

WP Associate Post R2 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The wp-associate-post-r2 v5.0.1 plugin exhibits a generally good security posture based on the provided static analysis. It has a minimal attack surface with only one AJAX handler, and importantly, no unprotected entry points. The code also demonstrates good practices by utilizing prepared statements for a majority of its SQL queries and incorporating nonce and capability checks. The absence of any recorded vulnerabilities or CVEs in its history is a significant strength, suggesting a history of stable and secure development.

However, there are areas for improvement that slightly elevate the risk profile. The taint analysis revealed two flows with unsanitized paths, which, while not classified as critical or high severity in this report, represent a potential vector for malicious input to be processed without proper sanitization. Furthermore, the output escaping is only properly implemented in 30% of cases, which is a notable concern. This could lead to cross-site scripting (XSS) vulnerabilities if user-controlled input is reflected in the output without adequate escaping. The presence of file operations and external HTTP requests, while not inherently insecure, warrants careful review to ensure they are handled securely and do not introduce additional risks. The bundled TinyMCE library, while common, should also be monitored for potential vulnerabilities in its specific version.

In conclusion, wp-associate-post-r2 v5.0.1 is a plugin with a strong foundation of secure coding practices, evidenced by its limited attack surface and lack of historical vulnerabilities. The primary areas of concern are the identified unsanitized paths and the low percentage of properly escaped output. Addressing these specific issues would significantly strengthen its security posture.

Key Concerns

  • Flows with unsanitized paths detected
  • Only 30% of output properly escaped
Vulnerabilities
None known

WP Associate Post R2 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Associate Post R2 Release Timeline

v5.0.1Current
v5.0.0
v4.2
v4.1
v4.0
v3.1
v3.0
v2.3
v2.2
v2.1
v2.0
v1.3
v1.2
v1.1
Code Analysis
Analyzed Mar 16, 2026

WP Associate Post R2 Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
8 prepared
Unescaped Output
102
44 escaped
Nonce Checks
3
Capability Checks
4
File Operations
1
External Requests
3
Bundled Libraries
1

Bundled Libraries

TinyMCE

SQL Query Safety

80% prepared10 total queries

Output Escaping

30% escaped146 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
item_search (classes\class-main.php:437)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Associate Post R2 Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_wpap-cache-clearclasses\class-main.php:88
WordPress Hooks 14
actionadmin_menuclasses\class-main.php:63
actionadmin_initclasses\class-main.php:64
actionenqueue_block_editor_assetsclasses\class-main.php:78
actionwp_enqueue_scriptsclasses\class-main.php:82
actionadmin_enqueue_scriptsclasses\class-main.php:89
filterplugin_action_linksclasses\class-main.php:90
filterplugin_row_metaclasses\class-main.php:91
actionmedia_buttonsclasses\class-main.php:92
filtermedia_upload_tabsclasses\class-main.php:97
filtermce_cssclasses\class-main.php:100
filtermce_external_pluginsclasses\class-main.php:102
actionwpmu_new_blogwp-associate-post-r2.php:48
actiondelete_blogwp-associate-post-r2.php:49
actioninitwp-associate-post-r2.php:52
Maintenance & Trust

WP Associate Post R2 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 16, 2025
PHP min version7.3
Downloads36K

Community Trust

Rating0/100
Number of ratings0
Active installs3K
Developer Profile

WP Associate Post R2 Developer Profile

Delight Star Inc.

2 plugins · 3K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Associate Post R2

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-associate-post-r2/css/skin-standard.css/wp-content/plugins/wp-associate-post-r2/css/skin-square.css/wp-content/plugins/wp-associate-post-r2/css/skin-circle.css/wp-content/plugins/wp-associate-post-r2/css/skin-weave.css/wp-content/plugins/wp-associate-post-r2/css/skin-shadow.css/wp-content/plugins/wp-associate-post-r2/js/click-tracking.js/wp-content/plugins/wp-associate-post-r2/css/admin-front.css
Script Paths
/wp-content/plugins/wp-associate-post-r2/js/click-tracking.js
Version Parameters
wp-associate-post-r2/css/skin-standard.css?ver=wp-associate-post-r2/css/skin-square.css?ver=wp-associate-post-r2/css/skin-circle.css?ver=wp-associate-post-r2/css/skin-weave.css?ver=wp-associate-post-r2/css/skin-shadow.css?ver=wp-associate-post-r2/js/click-tracking.js?ver=wp-associate-post-r2/css/admin-front.css?ver=

HTML / DOM Fingerprints

JS Globals
wpapBlockConfig
FAQ

Frequently Asked Questions about WP Associate Post R2