Hamazon Security & Risk Analysis

wordpress.org/plugins/wp-hamazon

You can add affiliate link in post content via Amazon, iTunes, DMM.

100 active installs v6.0.0 PHP 8.1+ WP 6.1+ Updated Jan 30, 2026
affiliateamazondmmphg
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hamazon Safe to Use in 2026?

Generally Safe

Score 100/100

Hamazon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "wp-hamazon" v6.0.0 plugin exhibits a strong security posture. The absence of any identified attack surface points, such as unprotected AJAX handlers, REST API routes, shortcodes, or cron events, is a significant strength. Furthermore, the code's adherence to secure coding practices is evident in the exclusive use of prepared statements for all SQL queries and a very high percentage of properly escaped output. The presence of bundled libraries like Guzzle, while noted, does not inherently pose a risk without further analysis of its specific version and potential vulnerabilities. The complete lack of any recorded vulnerabilities (CVEs) over time suggests a history of secure development or diligent patching by the maintainers. However, the absence of nonce checks and capability checks is a potential concern. While the static analysis did not reveal any exploitable flows, these checks are crucial for preventing cross-site request forgery (CSRF) and unauthorized actions, especially if new entry points are introduced or existing ones are modified in future updates. The file operations and external HTTP requests are also areas that warrant careful consideration in a deeper review to ensure they are handled securely and do not expose the system to risks.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Hamazon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Hamazon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
106 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
3
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

95% escaped111 total outputs
Attack Surface

Hamazon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actioninitapp\Hametuha\WpHamazon\BlockEditor.php:21
actionadmin_menuapp\Hametuha\WpHamazon\BootStrap.php:33
actionadmin_initapp\Hametuha\WpHamazon\BootStrap.php:35
actioninitapp\Hametuha\WpHamazon\BootStrap.php:37
filterplugin_action_linksapp\Hametuha\WpHamazon\BootStrap.php:39
actionwp_enqueue_scriptsapp\Hametuha\WpHamazon\BootStrap.php:41
filtermce_cssapp\Hametuha\WpHamazon\BootStrap.php:65
actionwp_enqueue_scriptsapp\Hametuha\WpHamazon\BootStrap.php:67
actionmedia_buttonsapp\Hametuha\WpHamazon\BootStrap.php:79
actionadmin_enqueue_scriptsapp\Hametuha\WpHamazon\BootStrap.php:94
actionadmin_initapp\Hametuha\WpHamazon\Pattern\AbstractService.php:47
actionrest_api_initapp\Hametuha\WpHamazon\Pattern\AbstractService.php:49
filterhamazon_service_variablesapp\Hametuha\WpHamazon\Pattern\AbstractService.php:51
actioninitapp\Hametuha\WpHamazon\Pattern\AbstractService.php:57
actionregister_shortcode_uiapp\Hametuha\WpHamazon\Pattern\AbstractService.php:104
actionplugins_loadedwp-hamazon.php:21
actionadmin_noticeswp-hamazon.php:50
actioninitwp-hamazon.php:56
Maintenance & Trust

Hamazon Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 30, 2026
PHP min version8.1
Downloads8K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Hamazon Developer Profile

Fumiki Takahashi

14 plugins · 4K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
513 days
View full developer profile
Detection Fingerprints

How We Detect Hamazon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/BlockEditor/block.js/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/BlockEditor/block.style.css/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/BlockEditor/editor.js/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/css/hamazon-admin.css/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/css/hamazon-style.css/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/js/hamazon-common.js/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/js/hamazon-editor.js/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/js/hamazon-media-frame.js+3 more
Script Paths
/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/BlockEditor/block.js/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/BlockEditor/editor.js/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/js/hamazon-common.js/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/js/hamazon-editor.js/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/js/hamazon-media-frame.js/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/js/hamazon-post.js+2 more
Version Parameters
/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/BlockEditor/block.js?ver=/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/BlockEditor/block.style.css?ver=/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/BlockEditor/editor.js?ver=/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/css/hamazon-admin.css?ver=/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/css/hamazon-style.css?ver=/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/js/hamazon-common.js?ver=/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/js/hamazon-editor.js?ver=/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/js/hamazon-media-frame.js?ver=/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/js/hamazon-post.js?ver=/wp-content/plugins/wp-hamazon/app/Hametuha/WpHamazon/js/hamazon-setting.js?ver=/wp-content/plugins/wp-hamazon/vendor/components/jquery/jquery.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
hamazon-inline-blockhamazon-setting-generalhamazon-post-typeshamazon-load-css
Data Attributes
name="hamazon_post_types[]"name="hamazon_load_css"
JS Globals
window.hamazon_i18n
REST Endpoints
/wp-json/wp/v2/hamazon/
Shortcode Output
[hamazon-product[hamazon-products[hamazon-slider[hamazon-ranking
FAQ

Frequently Asked Questions about Hamazon