
AffiliateWP – Allow Own Referrals Security & Risk Analysis
wordpress.org/plugins/affiliatewp-allow-own-referralsAllows an affiliate to earn commission on their own referral links.
Is AffiliateWP – Allow Own Referrals Safe to Use in 2026?
Generally Safe
Score 100/100AffiliateWP – Allow Own Referrals has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, the "affiliatewp-allow-own-referrals" v1.2.1 plugin appears to have a very strong security posture. The absence of any identified dangerous functions, SQL queries not using prepared statements, and all output being properly escaped are excellent indicators of good coding practices. Furthermore, the lack of file operations, external HTTP requests, and the absence of any identified taint flows with unsanitized paths significantly reduces the potential attack surface.
The vulnerability history is also completely clean, with no recorded CVEs of any severity. This indicates a well-maintained and secure plugin over time, or at least that no significant vulnerabilities have been publicly disclosed for this plugin. The plugin also demonstrates a robust use of WordPress security features by not exposing any AJAX handlers, REST API routes, shortcodes, or cron events without appropriate authentication or capability checks, as evidenced by the 'Unprotected: 0' metrics across all attack surface categories.
Overall, this plugin exhibits a highly secure design and implementation. The lack of any identified vulnerabilities or insecure code patterns, combined with a clean history, suggests a low-risk plugin. The only area that could be noted as a weakness, though minor and not directly indicative of a problem in this specific case, is the complete absence of nonce and capability checks. While the static analysis reports no unprotected entry points, it's a practice that generally contributes to defense-in-depth. However, given the other strong security signals and clean history, this does not currently translate into a significant risk.
AffiliateWP – Allow Own Referrals Security Vulnerabilities
AffiliateWP – Allow Own Referrals Code Analysis
AffiliateWP – Allow Own Referrals Attack Surface
WordPress Hooks 5
Maintenance & Trust
AffiliateWP – Allow Own Referrals Maintenance & Trust
Maintenance Signals
Community Trust
AffiliateWP – Allow Own Referrals Alternatives
AffiliateWP – Affiliate Area Tabs
affiliatewp-affiliate-area-tabs
Add and reorder tabs in AffiliateWP's Affiliate Area
AffiliateWP – Affiliate Product Rates
affiliatewp-affiliate-product-rates
Allows you to set product referral rates on a per-affiliate level in AffiliateWP.
AffiliateWP – Order Details For Affiliates
affiliatewp-order-details-for-affiliates
Allow affiliates to see order details on referrals they generated
AffiliateWP – Affiliate Info
affiliatewp-affiliate-info
Display information based on the affiliate's referral URL.
AffiliateWP – Affiliate QR Codes
affiliatewp-affiliate-qr-codes
Allows affiliates to save, print, or share their affiliate URL as a QR code.
AffiliateWP – Allow Own Referrals Developer Profile
94 plugins · 23.5M total installs
How We Detect AffiliateWP – Allow Own Referrals
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/affiliatewp-allow-own-referrals/includes/lib/affwp/js/affwp-admin-notice.js/wp-content/plugins/affiliatewp-allow-own-referrals/assets/css/aor-admin-notice.css/wp-content/plugins/affiliatewp-allow-own-referrals/includes/lib/affwp/js/affwp-admin-notice.jsaffiliatewp-allow-own-referrals/assets/css/aor-admin-notice.css?ver=affiliatewp-allow-own-referrals/includes/lib/affwp/js/affwp-admin-notice.js?ver=HTML / DOM Fingerprints
affwp-aor-admin-notice