Affiliate Coupons for Woocommerce Security & Risk Analysis

wordpress.org/plugins/affiliate-coupon-codes-for-woocommerce

Create and add affiliates to Woocommerce coupon codes and generate a report for commissions and payouts.

0 active installs v2.1 PHP + WP 3.0+ Updated Apr 24, 2025
affiliateaffiliate-couponsaffiliate-coupons-woocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Affiliate Coupons for Woocommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Affiliate Coupons for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'affiliate-coupon-codes-for-woocommerce' plugin v2.1 exhibits a generally strong security posture based on the static analysis. The absence of direct entry points like AJAX handlers, REST API routes, and shortcodes significantly reduces the attack surface. Furthermore, the use of prepared statements for all SQL queries and a high percentage of properly escaped output indicate good coding practices for preventing common web vulnerabilities. The lack of recorded vulnerabilities, including CVEs, is also a positive indicator of the plugin's security.

However, the analysis does highlight a couple of potential areas of concern. The presence of two taint flows with unsanitized paths, even though they are not classified as critical or high severity, warrants attention. This suggests that there might be instances where user-supplied data is not being adequately validated or sanitized before being processed, which could potentially lead to unexpected behavior or be leveraged in more complex attack chains. The complete absence of nonce and capability checks across all identified entry points is also a significant weakness, as it leaves the plugin susceptible to CSRF attacks if any of its functionalities were to be exposed through future updates or hidden entry points.

In conclusion, the plugin demonstrates a good foundation in terms of preventing common vulnerabilities like SQL injection and XSS through its use of prepared statements and output escaping. The clean vulnerability history further bolsters this assessment. Nevertheless, the identified unsanitized taint flows and the lack of nonce/capability checks represent critical omissions that, if exploited, could pose a security risk. Developers should prioritize addressing these areas to further harden the plugin's security.

Key Concerns

  • Unsanitized taint flows found
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Affiliate Coupons for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Affiliate Coupons for Woocommerce Release Timeline

v2.1Current
v2.0
v1.0
Code Analysis
Analyzed Mar 17, 2026

Affiliate Coupons for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
10
64 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

86% escaped74 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
affiliate_coupons_reports (affiliate-coupons-woo-loda.php:722)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Affiliate Coupons for Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadd_meta_boxesaffiliate-coupons-woo-loda.php:43
actionwoocommerce_update_couponaffiliate-coupons-woo-loda.php:53
actionadmin_menuaffiliate-coupons-woo-loda.php:152
actionwoocommerce_checkout_create_orderaffiliate-coupons-woo-loda.php:372
filterwoocommerce_order_data_store_cpt_get_orders_queryaffiliate-coupons-woo-loda.php:516
actioninitaffiliate-coupons-woo-loda.php:533
filterquery_varsaffiliate-coupons-woo-loda.php:562
filterwoocommerce_account_menu_itemsaffiliate-coupons-woo-loda.php:576
actionwoocommerce_account_loda-affiliate-coupons_endpointaffiliate-coupons-woo-loda.php:718
Maintenance & Trust

Affiliate Coupons for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.6
Last updatedApr 24, 2025
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Affiliate Coupons for Woocommerce Developer Profile

pheromonetreasures

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Affiliate Coupons for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliate-coupon-codes-for-woocommerce/affiliate_coupons_admin_menu.js/wp-content/plugins/affiliate-coupon-codes-for-woocommerce/assets/css/affiliate_coupons_admin_menu.css
Script Paths
/wp-content/plugins/affiliate-coupon-codes-for-woocommerce/affiliate_coupons_admin_menu.js
Version Parameters
affiliate-coupon-codes-for-woocommerce/affiliate_coupons_admin_menu.js?ver=affiliate-coupon-codes-for-woocommerce/assets/css/affiliate_coupons_admin_menu.css?ver=

HTML / DOM Fingerprints

CSS Classes
affselectaffsearchwrap
HTML Comments
<!-- Filters the useres search box--><!-- Displaying content in the meta container on admin shop_coupon pages --><!-- main affiliate coupons page admin menu -->
Data Attributes
id="myInputz69"name="authorCC"id="authorCC"name="author"id="coupon_usage_data"
JS Globals
lodaFilterFunctionChangedSelection
FAQ

Frequently Asked Questions about Affiliate Coupons for Woocommerce