AffiliateWP – Affiliate Area Tabs Security & Risk Analysis

wordpress.org/plugins/affiliatewp-affiliate-area-tabs

Add and reorder tabs in AffiliateWP's Affiliate Area

4K active installs v1.4.2 PHP 7.4+ WP 5.2+ Updated May 20, 2025
affiliate-areaaffiliate-dashboardaffiliatewpcustom-tabs
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AffiliateWP – Affiliate Area Tabs Safe to Use in 2026?

Generally Safe

Score 100/100

AffiliateWP – Affiliate Area Tabs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The static analysis of the affiliatewp-affiliate-area-tabs plugin v1.4.2 reveals a generally strong security posture with no identified dangerous functions, SQL injection vulnerabilities, or file operations. The absence of external HTTP requests and bundled libraries is also a positive sign. However, the analysis indicates a significant concern regarding output escaping, with only 25% of outputs being properly escaped. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities where user-supplied data might be rendered directly in the browser without adequate sanitization, allowing attackers to inject malicious scripts.

The plugin's vulnerability history is clean, with no recorded CVEs. This, coupled with the lack of any critical or high-severity taint analysis findings, implies that the plugin has historically been maintained with security in mind or has not attracted significant security research. Despite the lack of known vulnerabilities, the high percentage of unescaped outputs remains a notable weakness that could be exploited. The absence of any identified entry points or unprotected handlers might seem positive, but it could also be an artifact of the static analysis tool's limitations or the specific functionality of the plugin, which might not expose direct interaction points to the analyzed code.

In conclusion, while the plugin benefits from a clean vulnerability history and the absence of certain high-risk code patterns, the low percentage of properly escaped outputs presents a clear and present risk. Developers should prioritize addressing this to mitigate potential XSS vulnerabilities. The lack of identified entry points is reassuring but should be viewed in conjunction with the output escaping issue. The overall security is decent, but the identified output escaping weakness prevents it from being excellent.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

AffiliateWP – Affiliate Area Tabs Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AffiliateWP – Affiliate Area Tabs Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped36 total outputs
Attack Surface

AffiliateWP – Affiliate Area Tabs Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionaffwp_plugins_loadedaffiliatewp-affiliate-area-tabs.php:188
actionplugins_loadedaffiliatewp-affiliate-area-tabs.php:190
actionadmin_noticesincludes\class-activation.php:69
actionadmin_noticesincludes\class-activation.php:80
filteraffwp_settings_tabsincludes\class-admin.php:6
filteraffwp_settingsincludes\class-admin.php:8
actionadmin_enqueue_scriptsincludes\class-admin.php:9
actionaffiliate_area_tabs_tab_rowincludes\class-admin.php:10
filterpre_update_option_affwp_settingsincludes\class-admin.php:11
filterplugin_row_metaincludes\class-affiliatewp-affiliate-area-tabs.php:245
filteraffwp_render_affiliate_dashboard_tabincludes\class-affiliatewp-affiliate-area-tabs.php:248
actiontemplate_redirectincludes\class-affiliatewp-affiliate-area-tabs.php:251
filteraffwp_affiliate_area_tabsincludes\class-affiliatewp-affiliate-area-tabs.php:262
filteraffwp_affiliate_area_show_tabincludes\class-affiliatewp-affiliate-area-tabs.php:267
actionaffwp_affiliate_dashboard_tabsincludes\class-compatibility.php:7
filteraffwp_affiliate_area_tabsincludes\class-compatibility.php:10
actionaffwp_affiliate_dashboard_bottomincludes\class-compatibility.php:13
actionadmin_initincludes\class-upgrades.php:31
Maintenance & Trust

AffiliateWP – Affiliate Area Tabs Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 20, 2025
PHP min version7.4
Downloads70K

Community Trust

Rating100/100
Number of ratings1
Active installs4K
Developer Profile

AffiliateWP – Affiliate Area Tabs Developer Profile

Syed Balkhi

94 plugins · 23.5M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
795 days
View full developer profile
Detection Fingerprints

How We Detect AffiliateWP – Affiliate Area Tabs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliatewp-affiliate-area-tabs/assets/css/admin.css/wp-content/plugins/affiliatewp-affiliate-area-tabs/assets/css/frontend.css
Script Paths
/wp-content/plugins/affiliatewp-affiliate-area-tabs/assets/js/admin.js
Version Parameters
affiliatewp-affiliate-area-tabs/assets/css/admin.css?ver=affiliatewp-affiliate-area-tabs/assets/css/frontend.css?ver=affiliatewp-affiliate-area-tabs/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
affwp-aat-tab-preview
Data Attributes
data-affwp-aat-tab-id
FAQ

Frequently Asked Questions about AffiliateWP – Affiliate Area Tabs