* The plugin download does not include a licence file, nor explicitly state the licence in the code.
* The logic looks like it might use the author's Amazon affiliate code 2 in 10 times, not 1 in 10 as stated. And always if not yet configured.
* The plugin enqueues a js file from the author's site which contains their Amazon codes again, but which could be changed at any time to execute any arbitrary JavaScript code.
* The author is leaving inappropriate comments on unrelated blog posts advertising the plugin! And under different names!