Bol.com Partnerprogramma by Biz2Web Security & Risk Analysis

wordpress.org/plugins/wp-bolcom-affiliates

Bol.com Partnerprogramma by Biz2Web enables site owners to insert Bol.com Partnerprogramma links into any page or post.

10 active installs v1.0.2 PHP + WP 3.4.1+ Updated May 25, 2018
affiliatesbol-compartnerprogramma
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bol.com Partnerprogramma by Biz2Web Safe to Use in 2026?

Generally Safe

Score 85/100

Bol.com Partnerprogramma by Biz2Web has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The wp-bolcom-affiliates plugin, version 1.0.2, presents a generally positive security posture, with no recorded vulnerabilities and a strong adherence to secure coding practices in several key areas. The absence of dangerous functions, raw SQL queries, and file operations is commendable. Furthermore, the plugin demonstrates an awareness of security by implementing capability checks. The limited attack surface and the fact that all identified entry points are protected by authentication checks are significant strengths.

However, there are notable areas for improvement. The plugin exhibits a concerningly low percentage of properly escaped output, meaning that user-supplied data might be rendered directly into the browser, potentially opening the door to cross-site scripting (XSS) vulnerabilities. The lack of nonce checks on any of its entry points is another significant weakness, as nonces are crucial for preventing cross-site request forgery (CSRF) attacks. While taint analysis showed no critical or high severity flows, the overall lack of analysis in this area, combined with the output escaping issues, suggests that deeper analysis might reveal previously undetected risks.

In conclusion, while the plugin has a clean vulnerability history and implements some good security practices, the identified weaknesses in output escaping and the complete absence of nonce checks pose a tangible risk. These areas require immediate attention to bolster the plugin's overall security and protect users from potential XSS and CSRF attacks.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • Limited taint analysis coverage
Vulnerabilities
None known

Bol.com Partnerprogramma by Biz2Web Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Bol.com Partnerprogramma by Biz2Web Release Timeline

v1.0.2Current
v1.0.1
v1.0
Code Analysis
Analyzed Mar 17, 2026

Bol.com Partnerprogramma by Biz2Web Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
3 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

43% escaped7 total outputs
Attack Surface

Bol.com Partnerprogramma by Biz2Web Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[bcproduct] main.php:64
[bclink] main.php:65
[bcp] main.php:68
[bcl] main.php:69
WordPress Hooks 10
actioninitmain.php:35
actionplugins_loadedmain.php:36
actiontemplate_redirectmain.php:37
actionwp_footermain.php:38
actionadmin_initmain.php:40
actionadmin_menumain.php:41
actionadmin_enqueue_scriptsmain.php:219
filtermce_buttonsmain.php:220
filtermce_external_pluginsmain.php:221
actionadmin_noticesmain.php:234
Maintenance & Trust

Bol.com Partnerprogramma by Biz2Web Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMay 25, 2018
PHP min version
Downloads2K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

Bol.com Partnerprogramma by Biz2Web Developer Profile

Biz2Web

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bol.com Partnerprogramma by Biz2Web

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-bolcom-affiliates/load.php/wp-content/plugins/wp-bolcom-affiliates/shortcode.js/wp-content/plugins/wp-bolcom-affiliates/quicktags.js/wp-content/plugins/wp-bolcom-affiliates/tinymce.js
Script Paths
/wp-content/plugins/wp-bolcom-affiliates/shortcode.js/wp-content/plugins/wp-bolcom-affiliates/quicktags.js/wp-content/plugins/wp-bolcom-affiliates/tinymce.js
Version Parameters
wp-bolcom-affiliates/shortcode.js?ver=wp-bolcom-affiliates/quicktags.js?ver=wp-bolcom-affiliates/tinymce.js?ver=

HTML / DOM Fingerprints

JS Globals
wpbol_shortcode_datawp_url
Shortcode Output
<div id='</a>
FAQ

Frequently Asked Questions about Bol.com Partnerprogramma by Biz2Web