
Affiliate Power – Sales Tracking for Affiliate Marketers Security & Risk Analysis
wordpress.org/plugins/affiliate-powerAffiliate Power imports your sales of various affiliate networks. Thanks to the additional tracking of posts, referer, URL-Parameters and devices, you …
Is Affiliate Power – Sales Tracking for Affiliate Marketers Safe to Use in 2026?
Generally Safe
Score 92/100Affiliate Power – Sales Tracking for Affiliate Marketers has a strong security track record. Known vulnerabilities have been patched promptly.
The "affiliate-power" plugin v2.5.0 exhibits a mixed security posture. While it demonstrates some good practices such as a high percentage of SQL queries using prepared statements and a reasonable number of nonce and capability checks, significant concerns arise from its attack surface and output sanitization. The presence of an unprotected AJAX handler creates a direct entry point for potential attacks, especially when combined with other identified weaknesses.
The static analysis reveals a concerning lack of proper output escaping, with only 19% of outputs being correctly sanitized. This, coupled with a taint analysis indicating flows with unsanitized paths, suggests a susceptibility to Cross-Site Scripting (XSS) vulnerabilities. The use of the dangerous `unserialize` function, while not directly linked to a specific vulnerability in the provided data, is a known risk factor that can lead to Remote Code Execution if not handled with extreme caution and validation.
The vulnerability history shows one past medium severity CVE related to XSS, which aligns with the findings from the static analysis. Although there are no currently unpatched vulnerabilities, the pattern of past XSS issues highlights a persistent area of weakness. In conclusion, while the plugin has some strengths, the unprotected entry points and significant output escaping deficiencies, combined with the historical XSS vulnerability, elevate the risk profile. It's crucial to address these specific code-level issues to improve the overall security of the plugin.
Key Concerns
- Unprotected AJAX handler
- Low percentage of properly escaped output
- Taint flows with unsanitized paths
- Use of dangerous unserialize function
- Past medium severity CVE (XSS)
Affiliate Power – Sales Tracking for Affiliate Marketers Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Affiliate Power – Sales Tracking for Affiliate Marketers <= 2.2.0 - Reflected Cross-Site Scripting
Affiliate Power – Sales Tracking for Affiliate Marketers Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Affiliate Power – Sales Tracking for Affiliate Marketers Attack Surface
AJAX Handlers 2
WordPress Hooks 15
Scheduled Events 1
Maintenance & Trust
Affiliate Power – Sales Tracking for Affiliate Marketers Maintenance & Trust
Maintenance Signals
Community Trust
Affiliate Power – Sales Tracking for Affiliate Marketers Alternatives
PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin
pretty-link
🌠 The best WordPress link management, branding, tracking, sharing and payments plugin. Easily make pretty & trackable shortlinks. 🔗
ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin
thirstyaffiliates
🔗 Affiliate link management & cloaker tool. Easily manage, shrink and track your affiliate links in WordPress. 🔥
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display
affiliate-toolkit-starter
Fast & Compatible with every WordPress Theme: With our plugin for WordPress, you can easily create and add your affiliate products to your website.
Affiliate Sales in Google Analytics and other tools
wecantrack
Integrate all your affiliate sales in Google Analytics, Google Ads, Facebook, Data Studio and more!
AffiliateWP – Affiliate Info
affiliatewp-affiliate-info
Display information based on the affiliate's referral URL.
Affiliate Power – Sales Tracking for Affiliate Marketers Developer Profile
2 plugins · 110 total installs
How We Detect Affiliate Power – Sales Tracking for Affiliate Marketers
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/affiliate-power/css/affiliate-power.css/wp-content/plugins/affiliate-power/css/affiliate-power-admin.css/wp-content/plugins/affiliate-power/js/affiliate-power-admin.js/wp-content/plugins/affiliate-power/js/affiliate-power-admin.jsaffiliate-power/css/affiliate-power.css?ver=affiliate-power/css/affiliate-power-admin.css?ver=affiliate-power/js/affiliate-power-admin.js?ver=HTML / DOM Fingerprints
affiliate-power-postpone-infotextaffiliate-power-hide-infotext