WP ClickBank Vendor Security & Risk Analysis

wordpress.org/plugins/wp-clickbank-vendor

Start selling your digital content, ebooks and software via ClickBank in minutes. WP ClickBank Vendor enables you to accept payments within minutes.

10 active installs v0.9.1 PHP 5.3+ WP 3.0.0+ Updated Jan 27, 2018
affiliateclickbanksellingvendor
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP ClickBank Vendor Safe to Use in 2026?

Generally Safe

Score 85/100

WP ClickBank Vendor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The wp-clickbank-vendor plugin v0.9.1 exhibits a mixed security posture. On the positive side, it has no known vulnerabilities (CVEs) and demonstrates a good effort in securing its entry points, with no unprotected AJAX handlers or REST API routes, and a single shortcode with an apparent nonce check. The plugin also largely utilizes prepared statements for its SQL queries. However, several significant concerns are present. The presence of the `unserialize` function is a major red flag, as it can lead to Remote Code Execution if used with untrusted input, and this is not flagged as a potential risk in the taint analysis. Furthermore, a substantial portion of its output is not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. While the taint analysis shows no current flows, this could be an artifact of the analysis or the limited nature of the testing. The absence of any recorded vulnerabilities in its history might suggest good development practices or simply a lack of exposure/detection. Overall, while some good security practices are in place, the unescaped output and the high-risk `unserialize` function without apparent input validation present critical areas for concern.

Key Concerns

  • Unescaped output detected
  • Dangerous function 'unserialize' used
Vulnerabilities
None known

WP ClickBank Vendor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP ClickBank Vendor Code Analysis

Dangerous Functions
1
Raw SQL Queries
4
18 prepared
Unescaped Output
37
0 escaped
Nonce Checks
1
Capability Checks
4
File Operations
2
External Requests
0
Bundled Libraries
1

Dangerous Functions Found

unserialize$transaction->transaction = unserialize($transaction->transaction);app\Model\Transaction.php:19

Bundled Libraries

TinyMCE

SQL Query Safety

82% prepared22 total queries

Output Escaping

0% escaped37 total outputs
Attack Surface

WP ClickBank Vendor Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[pay] app\Common.php:52
WordPress Hooks 18
actionadmin_enqueue_scriptsapp\Admin.php:45
actionadmin_menuapp\Admin.php:64
actioninitapp\Admin.php:77
actionload-post.phpapp\Admin.php:78
actionload-post-new.phpapp\Admin.php:79
actioninitapp\Ajax.php:12
actionparse_requestapp\Common.php:49
actioninitapp\Common.php:50
actionadmin_footerapp\Controller\Admin\MCE.php:24
filtermce_external_pluginsapp\Controller\Admin\MCE.php:38
filtermce_buttonsapp\Controller\Admin\MCE.php:39
actionwp_footerapp\Controller\DownloadPageAccess.php:80
actionwpapp\Controller\DownloadPageAccess.php:111
actionadd_meta_boxesapp\Controller\Metabox\Product.php:60
actionsave_postapp\Controller\Metabox\Product.php:61
actioncurrent_screencore\Admin.php:54
actionadmin_enqueue_scriptscore\Controller.php:11
actionsave_postcore\Helper\Metabox.php:35
Maintenance & Trust

WP ClickBank Vendor Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 27, 2018
PHP min version5.3
Downloads13K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

WP ClickBank Vendor Developer Profile

Arevico

4 plugins · 110 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP ClickBank Vendor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-clickbank-vendor/app/public/css/customers.css/wp-content/plugins/wp-clickbank-vendor/app/public/css/product-information.css/wp-content/plugins/wp-clickbank-vendor/app/public/css/wp-clickbank-vendor.css/wp-content/plugins/wp-clickbank-vendor/app/public/js/customers.js/wp-content/plugins/wp-clickbank-vendor/app/public/js/product-information.js/wp-content/plugins/wp-clickbank-vendor/app/public/js/wp-clickbank-vendor.js/wp-content/plugins/wp-clickbank-vendor/core/public/vue/vue.js
Script Paths
/wp-content/plugins/wp-clickbank-vendor/core/public/vue/vue.js
Version Parameters
/wp-content/plugins/wp-clickbank-vendor/app/public/css/customers.css?ver=/wp-content/plugins/wp-clickbank-vendor/app/public/css/product-information.css?ver=/wp-content/plugins/wp-clickbank-vendor/app/public/css/wp-clickbank-vendor.css?ver=/wp-content/plugins/wp-clickbank-vendor/app/public/js/customers.js?ver=/wp-content/plugins/wp-clickbank-vendor/app/public/js/product-information.js?ver=/wp-content/plugins/wp-clickbank-vendor/app/public/js/wp-clickbank-vendor.js?ver=/wp-content/plugins/wp-clickbank-vendor/core/public/vue/vue.js?ver=

HTML / DOM Fingerprints

CSS Classes
arevico-cb-customer-editarevico-cb-customer-addarevico-cb-product-info-editarevico-cb-product-info-addarevico-cb-productsarevico-cb-sales-overview
HTML Comments
<!-- Arevico CB Customer Edit Form --><!-- Arevico CB Customer Add Form --><!-- Arevico CB Product Information Edit Form --><!-- Arevico CB Product Information Add Form -->
Data Attributes
data-vue-template='product-access-item'
JS Globals
Arevico_CB_Customers_EditArevico_CB_Customers_AddArevico_CB_ProductInformation_EditArevico_CB_ProductInformation_AddArevico_CB_ProductsArevico_CB_Sales_Overview
FAQ

Frequently Asked Questions about WP ClickBank Vendor