AffiliateWP – Allow Own Referrals Security & Risk Analysis

wordpress.org/plugins/affiliatewp-allow-own-referrals

Allows an affiliate to earn commission on their own referral links.

800 active installs v1.2.1 PHP 7.4+ WP 5.2+ Updated May 8, 2025
affiliate-purchaseaffiliatewpown-commissionown-referralsself-referral
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AffiliateWP – Allow Own Referrals Safe to Use in 2026?

Generally Safe

Score 100/100

AffiliateWP – Allow Own Referrals has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

Based on the static analysis, the "affiliatewp-allow-own-referrals" v1.2.1 plugin appears to have a very strong security posture. The absence of any identified dangerous functions, SQL queries not using prepared statements, and all output being properly escaped are excellent indicators of good coding practices. Furthermore, the lack of file operations, external HTTP requests, and the absence of any identified taint flows with unsanitized paths significantly reduces the potential attack surface.

The vulnerability history is also completely clean, with no recorded CVEs of any severity. This indicates a well-maintained and secure plugin over time, or at least that no significant vulnerabilities have been publicly disclosed for this plugin. The plugin also demonstrates a robust use of WordPress security features by not exposing any AJAX handlers, REST API routes, shortcodes, or cron events without appropriate authentication or capability checks, as evidenced by the 'Unprotected: 0' metrics across all attack surface categories.

Overall, this plugin exhibits a highly secure design and implementation. The lack of any identified vulnerabilities or insecure code patterns, combined with a clean history, suggests a low-risk plugin. The only area that could be noted as a weakness, though minor and not directly indicative of a problem in this specific case, is the complete absence of nonce and capability checks. While the static analysis reports no unprotected entry points, it's a practice that generally contributes to defense-in-depth. However, given the other strong security signals and clean history, this does not currently translate into a significant risk.

Vulnerabilities
None known

AffiliateWP – Allow Own Referrals Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AffiliateWP – Allow Own Referrals Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

AffiliateWP – Allow Own Referrals Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedaffiliatewp-allow-own-referrals.php:112
actionaffwp_plugins_loadedaffiliatewp-allow-own-referrals.php:114
filterplugin_row_metaincludes\class-affiliatewp-allow-own-referrals.php:199
filteraffwp_is_customer_email_affiliate_emailincludes\class-affiliatewp-allow-own-referrals.php:201
filteraffwp_tracking_is_valid_affiliateincludes\class-affiliatewp-allow-own-referrals.php:203
Maintenance & Trust

AffiliateWP – Allow Own Referrals Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 8, 2025
PHP min version7.4
Downloads17K

Community Trust

Rating0/100
Number of ratings0
Active installs800
Developer Profile

AffiliateWP – Allow Own Referrals Developer Profile

Syed Balkhi

94 plugins · 23.5M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
795 days
View full developer profile
Detection Fingerprints

How We Detect AffiliateWP – Allow Own Referrals

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliatewp-allow-own-referrals/includes/lib/affwp/js/affwp-admin-notice.js/wp-content/plugins/affiliatewp-allow-own-referrals/assets/css/aor-admin-notice.css
Script Paths
/wp-content/plugins/affiliatewp-allow-own-referrals/includes/lib/affwp/js/affwp-admin-notice.js
Version Parameters
affiliatewp-allow-own-referrals/assets/css/aor-admin-notice.css?ver=affiliatewp-allow-own-referrals/includes/lib/affwp/js/affwp-admin-notice.js?ver=

HTML / DOM Fingerprints

CSS Classes
affwp-aor-admin-notice
FAQ

Frequently Asked Questions about AffiliateWP – Allow Own Referrals