Affiliate Area Shortcodes by AffiliateWP Security & Risk Analysis

wordpress.org/plugins/affiliatewp-affiliate-area-shortcodes

Customize your affiliate dashboard with 20+ powerful shortcodes. Show earnings, stats, referrals, and graphs anywhere on your site.

2K active installs v1.3.1 PHP 7.4+ WP 5.2+ Updated Sep 11, 2025
affiliateaffiliate-areashortcodes
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Affiliate Area Shortcodes by AffiliateWP Safe to Use in 2026?

Generally Safe

Score 100/100

Affiliate Area Shortcodes by AffiliateWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "affiliatewp-affiliate-area-shortcodes" v1.3.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The high percentage of properly escaped output further reinforces this positive assessment.

However, a significant concern arises from the complete lack of nonce checks and capability checks across all entry points, particularly the 20 shortcodes. While the attack surface appears to be protected by WordPress's default authorization mechanisms for shortcodes, the absence of explicit checks is a potential weakness. If any shortcode logic relies on user-specific data or actions, the lack of these checks could expose it to unauthorized access or manipulation.

The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the static analysis findings, suggests the developers are likely following good coding practices. Nevertheless, the absence of explicit security checks on shortcodes remains the primary area of concern, as it relies heavily on WordPress's built-in, and sometimes implicit, security layers. A more robust approach would involve implementing explicit nonce and capability checks within the shortcode handlers themselves.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Affiliate Area Shortcodes by AffiliateWP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Affiliate Area Shortcodes by AffiliateWP Release Timeline

v1.3.1Current
v1.3.0
v1.2
v1.1.7
v1.1.6
v1.1.5
v1.1.4
v1.1.3
v1.1.2
v1.1.1
v1.1
Code Analysis
Analyzed Mar 16, 2026

Affiliate Area Shortcodes by AffiliateWP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
27 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped30 total outputs
Attack Surface

Affiliate Area Shortcodes by AffiliateWP Attack Surface

Entry Points20
Unprotected0

Shortcodes 20

[affiliate_area_graphs] includes\class-shortcodes.php:15
[affiliate_area_settings] includes\class-shortcodes.php:18
[affiliate_area_creatives] includes\class-shortcodes.php:21
[affiliate_area_referrals] includes\class-shortcodes.php:24
[affiliate_area_stats] includes\class-shortcodes.php:27
[affiliate_area_urls] includes\class-shortcodes.php:30
[affiliate_area_payouts] includes\class-shortcodes.php:33
[affiliate_area_visits] includes\class-shortcodes.php:36
[affiliate_referrals] includes\class-shortcodes.php:41
[affiliate_earnings] includes\class-shortcodes.php:44
[affiliate_visits] includes\class-shortcodes.php:47
[affiliate_conversion_rate] includes\class-shortcodes.php:50
[affiliate_commission_rate] includes\class-shortcodes.php:53
[affiliate_campaign_stats] includes\class-shortcodes.php:56
[affiliate_id] includes\class-shortcodes.php:59
[affiliate_username] includes\class-shortcodes.php:62
[affiliate_name] includes\class-shortcodes.php:65
[affiliate_website] includes\class-shortcodes.php:68
[affiliate_area_notices] includes\class-shortcodes.php:73
[affiliate_logout] includes\class-shortcodes.php:76
WordPress Hooks 6
actionplugins_loadedaffiliatewp-affiliate-area-shortcodes.php:106
actionadmin_noticesincludes\class-activation.php:95
actionadmin_enqueue_scriptsincludes\class-activation.php:96
filterplugin_row_metaincludes\class-affiliatewp-affiliate-area-shortcodes.php:213
filteraffwp_force_frontend_scriptsincludes\class-shortcodes.php:8
actionwp_enqueue_scriptsincludes\class-shortcodes.php:10
Maintenance & Trust

Affiliate Area Shortcodes by AffiliateWP Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 11, 2025
PHP min version7.4
Downloads44K

Community Trust

Rating80/100
Number of ratings5
Active installs2K
Developer Profile

Affiliate Area Shortcodes by AffiliateWP Developer Profile

Syed Balkhi

94 plugins · 23.5M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
752 days
View full developer profile
Detection Fingerprints

How We Detect Affiliate Area Shortcodes by AffiliateWP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliatewp-affiliate-area-shortcodes/includes/lib/affwp/css/affwp-admin-banner.css/wp-content/plugins/affiliatewp-affiliate-area-shortcodes/css/affiliate-area-shortcodes.css
Script Paths
/wp-content/plugins/affiliatewp-affiliate-area-shortcodes/includes/lib/affwp/js/affwp-admin-banner.js
Version Parameters
affiliatewp-affiliate-area-shortcodes/includes/lib/affwp/css/affwp-admin-banner.css?ver=affiliatewp-affiliate-area-shortcodes/css/affiliate-area-shortcodes.css?ver=affiliatewp-affiliate-area-shortcodes/includes/lib/affwp/js/affwp-admin-banner.js?ver=

HTML / DOM Fingerprints

CSS Classes
affwp-banneraffwp-banner__topaffwp-banner__inneraffwp-banner__contentaffwp-banner__logoaffwp-banner__title
Data Attributes
data-affwp-shortcode-id
JS Globals
AffiliateWP_Affiliate_Area_Shortcodes
Shortcode Output
[affwp_affiliate_area][affwp_affiliate_register][affwp_affiliate_login][affwp_affiliate_dashboard]
FAQ

Frequently Asked Questions about Affiliate Area Shortcodes by AffiliateWP