Affilia – Affiliate Program Security & Risk Analysis

wordpress.org/plugins/affiliaa-affiliate-program-with-mlm

Affilia is a self-hosted WordPress affiliate plugin for managing affiliates, referral links, commissions, dashboards, and records.

500 active installs v3.3.5 PHP 5.6.2+ WP 5.0+ Updated Jul 18, 2026
affiliate-managementaffiliate-pluginaffiliate-programaffiliateswoocommerce-affiliate
99
A · Safe
CVEs total1
Unpatched0
Last CVEJul 10, 2026
Safety Verdict

Is Affilia – Affiliate Program Safe to Use in 2026?

Generally Safe

Score 99/100

Affilia – Affiliate Program has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jul 10, 2026Updated 1mo ago
Risk Assessment

The plugin 'affiliaa-affiliate-program-with-mlm' v3.3.3 exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices, with a high percentage of SQL queries utilizing prepared statements and a significant majority of output being properly escaped. The plugin also implements a good number of nonce and capability checks, indicating an effort to protect its functionalities from unauthorized access. Furthermore, the complete absence of known vulnerabilities in its history suggests a well-maintained and secure codebase over time.

However, the taint analysis reveals a notable concern: three flows with unsanitized paths, all classified as high severity. While the static analysis reports no unprotected entry points, these unsanitized paths could potentially lead to injection vulnerabilities if they are reachable and exploitable. This is the primary area of concern in an otherwise robust security profile. The presence of bundled libraries like DataTables and Select2, while not inherently problematic, could become a risk if they are outdated and contain known vulnerabilities, although no such issues are reported currently.

In conclusion, the plugin is largely secure with good coding practices and a clean vulnerability history. The critical area to monitor and address are the three high-severity taint flows with unsanitized paths. Remediation of these specific code paths would further solidify the plugin's security, making it a reliable option.

Key Concerns

  • High severity taint flows with unsanitized paths
Vulnerabilities
1 published

Affilia – Affiliate Program Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-7559medium · 4.3Missing Authorization

Affilia <= 3.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Status Modification

Jul 10, 2026 Patched in 3.3.4 (1d)
Version History

Affilia – Affiliate Program Release Timeline

v3.3.4
v3.3.31 CVE
v3.3.21 CVE
v3.3.11 CVE
v3.3.01 CVE
v3.2.31 CVE
v3.2.21 CVE
v3.2.11 CVE
v3.2.01 CVE
v3.1.01 CVE
v3.0.01 CVE
v2.7.01 CVE
v2.6.01 CVE
v2.5.01 CVE
v2.4.01 CVE
v2.3.01 CVE
v2.2.01 CVE
v2.1.11 CVE
v2.1.01 CVE
v2.0.21 CVE
Code Analysis
Analyzed Mar 16, 2026

Affilia – Affiliate Program Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
52 prepared
Unescaped Output
26
521 escaped
Nonce Checks
15
Capability Checks
9
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

DataTablesSelect2

SQL Query Safety

96% prepared54 total queries

Output Escaping

95% escaped547 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

7 flows3 with unsanitized paths
<rtwalwm_affiliates> (admin\partials\rtwalwm_tabs\rtwalwm_affiliates.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Affilia – Affiliate Program Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[rtwwwap_affiliate_page] public\rtwalwm-class-wp-wc-affiliate-program-public.php:54
[rtwwwap_aff_login_page] public\rtwalwm-class-wp-wc-affiliate-program-public.php:55
WordPress Hooks 1
actionbefore_woocommerce_initwp-wc-affiliate-program.php:110
Maintenance & Trust

Affilia – Affiliate Program Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJul 18, 2026
PHP min version5.6.2
Downloads50K

Community Trust

Rating94/100
Number of ratings14
Active installs500
Developer Profile

Affilia – Affiliate Program Developer Profile

RedefiningTheWeb

6 plugins · 2K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
144 days
View full developer profile
Detection Fingerprints

How We Detect Affilia – Affiliate Program

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliaa-affiliate-program-with-mlm/assets/css/admin.css/wp-content/plugins/affiliaa-affiliate-program-with-mlm/assets/css/affiliatereferal.css/wp-content/plugins/affiliaa-affiliate-program-with-mlm/assets/js/admin.js/wp-content/plugins/affiliaa-affiliate-program-with-mlm/assets/js/affiliate.js
Script Paths
/wp-content/plugins/affiliaa-affiliate-program-with-mlm/assets/js/admin.js/wp-content/plugins/affiliaa-affiliate-program-with-mlm/assets/js/affiliate.js
Version Parameters
affiliaa-affiliate-program-with-mlm/assets/css/admin.css?ver=affiliaa-affiliate-program-with-mlm/assets/css/affiliatereferal.css?ver=affiliaa-affiliate-program-with-mlm/assets/js/admin.js?ver=affiliaa-affiliate-program-with-mlm/assets/js/affiliate.js?ver=

HTML / DOM Fingerprints

CSS Classes
rtwalwm-affiliate-dashboardrtwalwm-affiliate-user-dashboard
Data Attributes
rtwalwm_affiliate_users_dashboardrtwalwm_affiliate_users_pendingrtwalwm_affiliate_users_activertwalwm_affiliate_users_deletertwalwm_affiliate_details_user
JS Globals
rtwalwm_affiliate_data
Shortcode Output
[rtwalwm_affiliate_users_dashboard][rtwalwm_affiliate_users_pending][rtwalwm_affiliate_users_active][rtwalwm_affiliate_users_delete]
FAQ

Frequently Asked Questions about Affilia – Affiliate Program