Affiliate Power – Sales Tracking for Affiliate Marketers Security & Risk Analysis

wordpress.org/plugins/affiliate-power

Affiliate Power imports your sales of various affiliate networks. Thanks to the additional tracking of posts, referer, URL-Parameters and devices, you …

100 active installs v2.5.0 PHP 5.6+ WP 4.6+ Updated Feb 22, 2025
affiliateawinfinanceadsrevenue-attributiontracking
92
A · Safe
CVEs total1
Unpatched0
Last CVESep 13, 2021
Safety Verdict

Is Affiliate Power – Sales Tracking for Affiliate Marketers Safe to Use in 2026?

Generally Safe

Score 92/100

Affiliate Power – Sales Tracking for Affiliate Marketers has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 13, 2021Updated 1yr ago
Risk Assessment

The "affiliate-power" plugin v2.5.0 exhibits a mixed security posture. While it demonstrates some good practices such as a high percentage of SQL queries using prepared statements and a reasonable number of nonce and capability checks, significant concerns arise from its attack surface and output sanitization. The presence of an unprotected AJAX handler creates a direct entry point for potential attacks, especially when combined with other identified weaknesses.

The static analysis reveals a concerning lack of proper output escaping, with only 19% of outputs being correctly sanitized. This, coupled with a taint analysis indicating flows with unsanitized paths, suggests a susceptibility to Cross-Site Scripting (XSS) vulnerabilities. The use of the dangerous `unserialize` function, while not directly linked to a specific vulnerability in the provided data, is a known risk factor that can lead to Remote Code Execution if not handled with extreme caution and validation.

The vulnerability history shows one past medium severity CVE related to XSS, which aligns with the findings from the static analysis. Although there are no currently unpatched vulnerabilities, the pattern of past XSS issues highlights a persistent area of weakness. In conclusion, while the plugin has some strengths, the unprotected entry points and significant output escaping deficiencies, combined with the historical XSS vulnerability, elevate the risk profile. It's crucial to address these specific code-level issues to improve the overall security of the plugin.

Key Concerns

  • Unprotected AJAX handler
  • Low percentage of properly escaped output
  • Taint flows with unsanitized paths
  • Use of dangerous unserialize function
  • Past medium severity CVE (XSS)
Vulnerabilities
1

Affiliate Power – Sales Tracking for Affiliate Marketers Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-2678d2c6-055e-462e-99da-bdc81bcc3662-affiliate-powermedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affiliate Power – Sales Tracking for Affiliate Marketers <= 2.2.0 - Reflected Cross-Site Scripting

Sep 13, 2021 Patched in 2.3.0 (862d)
Code Analysis
Analyzed Mar 16, 2026

Affiliate Power – Sales Tracking for Affiliate Marketers Code Analysis

Dangerous Functions
1
Raw SQL Queries
12
43 prepared
Unescaped Output
25
6 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
19
Bundled Libraries
0

Dangerous Functions Found

unserialize$information = unserialize($http_answer['body']);affiliate-power.php:254

SQL Query Safety

78% prepared55 total queries

Output Escaping

19% escaped31 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

6 flows3 with unsanitized paths
statisticsPage (affiliate-power-statistics.php:8)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Affiliate Power – Sales Tracking for Affiliate Marketers Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 2

authwp_ajax_ap_export_csvaffiliate-power-transactions.php:11
authwp_ajax_ap_download_transactionsaffiliate-power.php:47
WordPress Hooks 15
actionaffiliate_power_daily_eventaffiliate-power-cron.php:10
actionaffiliate_power_daily_eventaffiliate-power-cron.php:11
actionaffiliate_power_daily_eventaffiliate-power-cron.php:12
actionadmin_menuaffiliate-power-menu.php:17
actionadmin_enqueue_scriptsaffiliate-power-menu.php:18
filterplugin_action_links_affiliate-power/affiliate-power.phpaffiliate-power-menu.php:20
filterprli_target_urlaffiliate-power-prli.php:6
actionadmin_initaffiliate-power-settings.php:13
actionwp_dashboard_setupaffiliate-power-widget.php:11
actioninitaffiliate-power.php:45
filterpre_set_site_transient_update_pluginsaffiliate-power.php:49
filterplugins_apiaffiliate-power.php:50
actionadmin_noticesaffiliate-power.php:115
actionadmin_noticesaffiliate-power.php:116
actionadmin_noticesaffiliate-power.php:163

Scheduled Events 1

affiliate_power_daily_event
Maintenance & Trust

Affiliate Power – Sales Tracking for Affiliate Marketers Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 22, 2025
PHP min version5.6
Downloads30K

Community Trust

Rating92/100
Number of ratings7
Active installs100
Developer Profile

Affiliate Power – Sales Tracking for Affiliate Marketers Developer Profile

JonasBreuer

2 plugins · 110 total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
862 days
View full developer profile
Detection Fingerprints

How We Detect Affiliate Power – Sales Tracking for Affiliate Marketers

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliate-power/css/affiliate-power.css/wp-content/plugins/affiliate-power/css/affiliate-power-admin.css/wp-content/plugins/affiliate-power/js/affiliate-power-admin.js
Script Paths
/wp-content/plugins/affiliate-power/js/affiliate-power-admin.js
Version Parameters
affiliate-power/css/affiliate-power.css?ver=affiliate-power/css/affiliate-power-admin.css?ver=affiliate-power/js/affiliate-power-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
affiliate-power-postpone-infotextaffiliate-power-hide-infotext
FAQ

Frequently Asked Questions about Affiliate Power – Sales Tracking for Affiliate Marketers