Affiliates WooCommerce Light Security & Risk Analysis

wordpress.org/plugins/affiliates-woocommerce-light

Grow your Business with your own Affiliate Network and let your partners earn commissions on referred sales. Integrates Affiliates and WooCommerce.

1K active installs v4.0.0 PHP 7.4+ WP 6.5+ Updated Feb 17, 2026
affiliateaffiliate-marketingaffiliatesreferralwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Affiliates WooCommerce Light Safe to Use in 2026?

Generally Safe

Score 100/100

Affiliates WooCommerce Light has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'affiliates-woocommerce-light' v4.0.0 demonstrates a generally strong security posture based on the provided static analysis. It exhibits zero known CVEs, indicating a history of responsible vulnerability management or a lack of historical issues. The absence of direct SQL queries without prepared statements and the high percentage of properly escaped output are positive signs. Furthermore, the plugin implements nonce and capability checks, which are crucial for preventing common WordPress vulnerabilities. The attack surface appears to be minimal, with no publicly exposed AJAX handlers, REST API routes, shortcodes, or cron events.

Despite these strengths, there is one significant concern: the presence of the `unserialize` function. This function can be a major security risk if it processes untrusted or user-supplied data, as it can lead to Remote Code Execution (RCE) vulnerabilities. While the static analysis doesn't report any taint flows involving `unserialize` in this specific version, its mere presence warrants caution, especially if future versions introduce new input sources. The lack of taint analysis flows is also a weakness, as it limits the depth of the analysis.

In conclusion, while the plugin has many good security practices in place and a clean vulnerability history, the use of `unserialize` is a notable weakness that could be exploited if not handled with extreme care to ensure all data passed to it is strictly controlled and validated. The minimal attack surface and robust checks are commendable, but the potential for `unserialize` vulnerabilities should not be overlooked.

Key Concerns

  • Dangerous function unserialize present
Vulnerabilities
None known

Affiliates WooCommerce Light Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Affiliates WooCommerce Light Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
2
11 escaped
Nonce Checks
1
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$data = unserialize( $data );affiliates-woocommerce-light.php:429
unserialize$data = unserialize( $data );affiliates-woocommerce-light.php:477

Output Escaping

85% escaped13 total outputs
Attack Surface

Affiliates WooCommerce Light Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actioninitaffiliates-woocommerce-light.php:183
actionadmin_noticesaffiliates-woocommerce-light.php:184
actionwoocommerce_checkout_order_processedaffiliates-woocommerce-light.php:200
actionwoocommerce_store_api_checkout_order_processedaffiliates-woocommerce-light.php:201
filteraffiliates_referral_post_permalinkaffiliates-woocommerce-light.php:203
filterpost_type_linkaffiliates-woocommerce-light.php:205
filteraffiliates_referral_post_titleaffiliates-woocommerce-light.php:208
actionaffiliates_admin_menuaffiliates-woocommerce-light.php:210
filteraffiliates_footeraffiliates-woocommerce-light.php:211
filteraffiliates_setup_buttonsaffiliates-woocommerce-light.php:212
filterwc_order_typesaffiliates-woocommerce-light.php:601
actionplugins_loadedaffiliates-woocommerce-light.php:651
actionbefore_woocommerce_initaffiliates-woocommerce-light.php:654
Maintenance & Trust

Affiliates WooCommerce Light Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 17, 2026
PHP min version7.4
Downloads135K

Community Trust

Rating100/100
Number of ratings6
Active installs1K
Developer Profile

Affiliates WooCommerce Light Developer Profile

itthinx

27 plugins · 23K total installs

98
trust score
Avg Security Score
97/100
Avg Patch Time
3 days
View full developer profile
Detection Fingerprints

How We Detect Affiliates WooCommerce Light

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliates-woocommerce-light/css/affiliates-woocommerce-light.css/wp-content/plugins/affiliates-woocommerce-light/js/affiliates-woocommerce-light.js
Script Paths
/wp-content/plugins/affiliates-woocommerce-light/js/affiliates-woocommerce-light.js
Version Parameters
affiliates-woocommerce-light/css/affiliates-woocommerce-light.css?ver=affiliates-woocommerce-light/js/affiliates-woocommerce-light.js?ver=

HTML / DOM Fingerprints

CSS Classes
affiliates-woocommerce-light
HTML Comments
<!-- Affiliates WooCommerce Light --><!-- Affiliates WooCommerce Light Integration -->
Data Attributes
data-plugin-name="Affiliates WooCommerce Light"data-plugin-version="4.0.0"
JS Globals
aff_woo_light_admin_options
FAQ

Frequently Asked Questions about Affiliates WooCommerce Light