
AffiliateWP – Affiliate QR Codes Security & Risk Analysis
wordpress.org/plugins/affiliatewp-affiliate-qr-codesAllows affiliates to save, print, or share their affiliate URL as a QR code.
Is AffiliateWP – Affiliate QR Codes Safe to Use in 2026?
Generally Safe
Score 85/100AffiliateWP – Affiliate QR Codes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security analysis of affiliatewp-affiliate-qr-codes v1.0.3 reveals a generally positive security posture, with no direct vulnerabilities or critical code signals detected. The plugin demonstrates good practices by not utilizing dangerous functions, all SQL queries are prepared, and there are no file operations or external HTTP requests. Taint analysis shows no unsanitized paths, indicating a lack of common input-related vulnerabilities. The absence of known CVEs further strengthens this assessment, suggesting a mature and well-maintained codebase. However, a significant concern is the complete lack of nonce checks and capability checks across all potential entry points, as well as a notable percentage of output that is not properly escaped. While the attack surface is currently reported as zero, this lack of authentication and authorization mechanisms on any future or unassessed entry points represents a substantial risk if the plugin were to evolve or if these entry points were discovered. The 75% output escaping is a weakness that could lead to Cross-Site Scripting (XSS) vulnerabilities if any of the unescaped outputs are user-controllable.
Key Concerns
- No nonce checks detected
- No capability checks detected
- 25% of output not properly escaped
AffiliateWP – Affiliate QR Codes Security Vulnerabilities
AffiliateWP – Affiliate QR Codes Release Timeline
AffiliateWP – Affiliate QR Codes Code Analysis
Output Escaping
AffiliateWP – Affiliate QR Codes Attack Surface
WordPress Hooks 7
Maintenance & Trust
AffiliateWP – Affiliate QR Codes Maintenance & Trust
Maintenance Signals
Community Trust
AffiliateWP – Affiliate QR Codes Alternatives
AffiliateWP – Affiliate Area Tabs
affiliatewp-affiliate-area-tabs
Add and reorder tabs in AffiliateWP's Affiliate Area
AffiliateWP – Affiliate Product Rates
affiliatewp-affiliate-product-rates
Allows you to set product referral rates on a per-affiliate level in AffiliateWP.
AffiliateWP – Order Details For Affiliates
affiliatewp-order-details-for-affiliates
Allow affiliates to see order details on referrals they generated
AffiliateWP – Affiliate Info
affiliatewp-affiliate-info
Display information based on the affiliate's referral URL.
AffiliateWP – Allowed Products
affiliatewp-allowed-products
Allows only specific products to generate commission in AffiliateWP.
AffiliateWP – Affiliate QR Codes Developer Profile
7 plugins · 4K total installs
How We Detect AffiliateWP – Affiliate QR Codes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/affiliatewp-affiliate-qr-codes/assets/css/affiliate-qr-codes.cssaffiliatewp-affiliate-qr-codes/assets/css/affiliate-qr-codes.css?ver=affiliatewp-affiliate-qr-codes/assets/js/affiliate-qr-codes.js?ver=HTML / DOM Fingerprints
affwp-aqrc-qr-code-wrapperdata-affwp-aqrc-qr-code-nonceaffwp_affiliate_qr_codes_generate_qr_code_params