WP G2A Goldmine CD Keys Affiliate Security & Risk Analysis

wordpress.org/plugins/wp-g2a-goldmine-cd-keys-affiliate

Search, Add & Manage G2A Goldmine REF Links. Display them direclty in your Wordpress! Earn money easily on every purchase your visitors make!

10 active installs v0.7.1.1 PHP + WP 4.0+ Updated Aug 30, 2020
affiliatecd-keysg2agamesgoldmine
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP G2A Goldmine CD Keys Affiliate Safe to Use in 2026?

Generally Safe

Score 85/100

WP G2A Goldmine CD Keys Affiliate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin "wp-g2a-goldmine-cd-keys-affiliate" v0.7.1.1 exhibits a generally good security posture based on the provided static analysis. All identified entry points (AJAX handlers, REST API routes, and shortcodes) appear to have authorization checks, which is a significant strength. The plugin also correctly uses prepared statements for its single SQL query, mitigating the risk of SQL injection. However, the static analysis reveals some concerning areas.

A notable weakness is the low percentage of properly escaped output (27%). This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, as unsanitized output can be injected with malicious scripts. Furthermore, the taint analysis shows two flows with unsanitized paths, suggesting potential for path traversal or similar vulnerabilities, although these were not classified as critical or high severity. The absence of nonce checks on any of the AJAX handlers is another critical oversight that could lead to Cross-Site Request Forgery (CSRF) attacks.

The plugin's vulnerability history is currently clear, with no known CVEs. This is a positive indicator, but it does not negate the risks identified in the code analysis. The lack of historical vulnerabilities could be due to the plugin's limited exposure, its relatively small attack surface, or simply a lack of comprehensive security auditing. In conclusion, while the plugin has strengths in authorization and SQL handling, the significant issues with output escaping and missing nonce checks present a considerable security risk that needs immediate attention.

Key Concerns

  • Low percentage of properly escaped output
  • Unsanitized paths in taint analysis flows
  • Missing nonce checks on AJAX handlers
Vulnerabilities
None known

WP G2A Goldmine CD Keys Affiliate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP G2A Goldmine CD Keys Affiliate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
48
18 escaped
Nonce Checks
0
Capability Checks
7
File Operations
2
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

27% escaped66 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
wpggma_resync_link (inc\ajax.php:276)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP G2A Goldmine CD Keys Affiliate Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 7

authwp_ajax_wpggma_activateinc\ajax.php:17
authwp_ajax_wpggma_check_refinc\ajax.php:47
authwp_ajax_wpggma_searchinc\ajax.php:204
authwp_ajax_wpggma_add_linkinc\ajax.php:251
authwp_ajax_wpggma_delete_linkinc\ajax.php:270
authwp_ajax_wpggma_resync_linkinc\ajax.php:330
authwp_ajax_wpggma_tool_parseinc\ajax.php:417

Shortcodes 1

[G2A] inc\functions.php:233
WordPress Hooks 12
actionadmin_initinc\hooks.php:4
filterpre_update_option_wpggma_RewriteBaseSluginc\hooks.php:13
filterpre_update_option_wpggma_RewriteGameSluginc\hooks.php:14
actionadmin_footerinc\hooks.php:21
actioninitinc\post-types.php:6
actionadmin_headinc\post-types.php:52
actioninitinc\post-types.php:61
filterpost_type_linkinc\post-types.php:66
actiontemplate_redirectinc\post-types.php:106
actionadmin_menuwp-g2a-goldmine.php:32
actionadmin_noticeswp-g2a-goldmine.php:110
actionadmin_initwp-g2a-goldmine.php:121
Maintenance & Trust

WP G2A Goldmine CD Keys Affiliate Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedAug 30, 2020
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

WP G2A Goldmine CD Keys Affiliate Developer Profile

Konrad Chmielewski

5 plugins · 130K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
177 days
View full developer profile
Detection Fingerprints

How We Detect WP G2A Goldmine CD Keys Affiliate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-g2a-goldmine-cd-keys-affiliate/css/admin.css/wp-content/plugins/wp-g2a-goldmine-cd-keys-affiliate/css/jquery.numberedtextarea.css/wp-content/plugins/wp-g2a-goldmine-cd-keys-affiliate/js/admin.js/wp-content/plugins/wp-g2a-goldmine-cd-keys-affiliate/js/jquery.numberedtextarea.js
Script Paths
/wp-content/plugins/wp-g2a-goldmine-cd-keys-affiliate/js/admin.js/wp-content/plugins/wp-g2a-goldmine-cd-keys-affiliate/js/jquery.numberedtextarea.js
Version Parameters
/wp-content/plugins/wp-g2a-goldmine-cd-keys-affiliate/css/admin.css?ver=/wp-content/plugins/wp-g2a-goldmine-cd-keys-affiliate/css/jquery.numberedtextarea.css?ver=/wp-content/plugins/wp-g2a-goldmine-cd-keys-affiliate/js/admin.js?ver=/wp-content/plugins/wp-g2a-goldmine-cd-keys-affiliate/js/jquery.numberedtextarea.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpggma_ActivateLink
FAQ

Frequently Asked Questions about WP G2A Goldmine CD Keys Affiliate