Affilia – Affiliate Program & Referral Tracking for WordPress Security & Risk Analysis

wordpress.org/plugins/affiliaa-affiliate-program-with-mlm

Launch a powerful, self-hosted affiliate program for WordPress. Track referrals, manage affiliates, and boost sales for WooCommerce, EDD, and Contact …

700 active installs v3.3.3 PHP 5.6.2+ WP 5.0+ Updated Feb 17, 2026
affiliate-programedd-affiliatereferral-trackingwoocommerce-affiliatewordpress-affiliate-plugin
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Affilia – Affiliate Program & Referral Tracking for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

Affilia – Affiliate Program & Referral Tracking for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'affiliaa-affiliate-program-with-mlm' v3.3.3 exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices, with a high percentage of SQL queries utilizing prepared statements and a significant majority of output being properly escaped. The plugin also implements a good number of nonce and capability checks, indicating an effort to protect its functionalities from unauthorized access. Furthermore, the complete absence of known vulnerabilities in its history suggests a well-maintained and secure codebase over time.

However, the taint analysis reveals a notable concern: three flows with unsanitized paths, all classified as high severity. While the static analysis reports no unprotected entry points, these unsanitized paths could potentially lead to injection vulnerabilities if they are reachable and exploitable. This is the primary area of concern in an otherwise robust security profile. The presence of bundled libraries like DataTables and Select2, while not inherently problematic, could become a risk if they are outdated and contain known vulnerabilities, although no such issues are reported currently.

In conclusion, the plugin is largely secure with good coding practices and a clean vulnerability history. The critical area to monitor and address are the three high-severity taint flows with unsanitized paths. Remediation of these specific code paths would further solidify the plugin's security, making it a reliable option.

Key Concerns

  • High severity taint flows with unsanitized paths
Vulnerabilities
None known

Affilia – Affiliate Program & Referral Tracking for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Affilia – Affiliate Program & Referral Tracking for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
52 prepared
Unescaped Output
26
521 escaped
Nonce Checks
15
Capability Checks
9
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

DataTablesSelect2

SQL Query Safety

96% prepared54 total queries

Output Escaping

95% escaped547 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

7 flows3 with unsanitized paths
<rtwalwm_affiliates> (admin\partials\rtwalwm_tabs\rtwalwm_affiliates.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Affilia – Affiliate Program & Referral Tracking for WordPress Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[rtwwwap_affiliate_page] public\rtwalwm-class-wp-wc-affiliate-program-public.php:54
[rtwwwap_aff_login_page] public\rtwalwm-class-wp-wc-affiliate-program-public.php:55
WordPress Hooks 1
actionbefore_woocommerce_initwp-wc-affiliate-program.php:110
Maintenance & Trust

Affilia – Affiliate Program & Referral Tracking for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 17, 2026
PHP min version5.6.2
Downloads48K

Community Trust

Rating94/100
Number of ratings14
Active installs700
Developer Profile

Affilia – Affiliate Program & Referral Tracking for WordPress Developer Profile

RedefiningTheWeb

6 plugins · 2K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
180 days
View full developer profile
Detection Fingerprints

How We Detect Affilia – Affiliate Program & Referral Tracking for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliaa-affiliate-program-with-mlm/assets/css/admin.css/wp-content/plugins/affiliaa-affiliate-program-with-mlm/assets/css/affiliatereferal.css/wp-content/plugins/affiliaa-affiliate-program-with-mlm/assets/js/admin.js/wp-content/plugins/affiliaa-affiliate-program-with-mlm/assets/js/affiliate.js
Script Paths
/wp-content/plugins/affiliaa-affiliate-program-with-mlm/assets/js/admin.js/wp-content/plugins/affiliaa-affiliate-program-with-mlm/assets/js/affiliate.js
Version Parameters
affiliaa-affiliate-program-with-mlm/assets/css/admin.css?ver=affiliaa-affiliate-program-with-mlm/assets/css/affiliatereferal.css?ver=affiliaa-affiliate-program-with-mlm/assets/js/admin.js?ver=affiliaa-affiliate-program-with-mlm/assets/js/affiliate.js?ver=

HTML / DOM Fingerprints

CSS Classes
rtwalwm-affiliate-dashboardrtwalwm-affiliate-user-dashboard
Data Attributes
rtwalwm_affiliate_users_dashboardrtwalwm_affiliate_users_pendingrtwalwm_affiliate_users_activertwalwm_affiliate_users_deletertwalwm_affiliate_details_user
JS Globals
rtwalwm_affiliate_data
Shortcode Output
[rtwalwm_affiliate_users_dashboard][rtwalwm_affiliate_users_pending][rtwalwm_affiliate_users_active][rtwalwm_affiliate_users_delete]
FAQ

Frequently Asked Questions about Affilia – Affiliate Program & Referral Tracking for WordPress