
AffiliateWP – External Referral Links Security & Risk Analysis
wordpress.org/plugins/affiliatewp-external-referral-linksAllows affiliates to promote external landing pages by including the affiliate's ID or username in any outbound links to your e-commerce store.
Is AffiliateWP – External Referral Links Safe to Use in 2026?
Generally Safe
Score 99/100AffiliateWP – External Referral Links has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of affiliatewp-external-referral-links v1.2.2 indicates a generally strong security posture with several good practices observed. Notably, there are no dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. The absence of file operations, external HTTP requests, and a large attack surface with unprotected entry points is also positive. However, the complete lack of nonce and capability checks across all entry points, while the entry point count is zero, presents a potential concern. If any entry points were introduced in future versions or through other means, their lack of authentication and authorization checks would be a significant risk.
The vulnerability history shows one known CVE, which is currently patched. The nature of the past vulnerability, 'Cross-site Scripting,' combined with the lack of specific checks (nonce, capability) suggests a historical pattern where input sanitization and proper authorization might have been a weak point. While no current vulnerabilities are identified in this version, this history warrants attention. The lack of taint analysis results is neutral, as it suggests no obvious vulnerabilities of that type were found, but doesn't fully alleviate concerns given the lack of explicit security checks.
In conclusion, affiliatewp-external-referral-links v1.2.2 demonstrates good coding practices in several key areas, leading to a solid foundation. The primary weakness lies in the complete absence of nonce and capability checks, which, while not immediately exploitable due to the zero attack surface, represents a latent risk. The historical vulnerability also highlights the need for continued vigilance regarding input validation and authorization mechanisms.
Key Concerns
- 0 nonce checks detected
- 0 capability checks detected
AffiliateWP – External Referral Links Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
AffiliateWP – External Referral Links <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
AffiliateWP – External Referral Links Code Analysis
Output Escaping
AffiliateWP – External Referral Links Attack Surface
WordPress Hooks 6
Maintenance & Trust
AffiliateWP – External Referral Links Maintenance & Trust
Maintenance Signals
Community Trust
AffiliateWP – External Referral Links Alternatives
Cross Domain Tracker for AffiliateWP
cross-domain-tracker-for-affiliatewp
Track referrals from different domains.
AffiliateWP – Affiliate Area Tabs
affiliatewp-affiliate-area-tabs
Add and reorder tabs in AffiliateWP's Affiliate Area
AffiliateWP – Affiliate Product Rates
affiliatewp-affiliate-product-rates
Allows you to set product referral rates on a per-affiliate level in AffiliateWP.
AffiliateWP – Order Details For Affiliates
affiliatewp-order-details-for-affiliates
Allow affiliates to see order details on referrals they generated
AffiliateWP – Affiliate Info
affiliatewp-affiliate-info
Display information based on the affiliate's referral URL.
AffiliateWP – External Referral Links Developer Profile
94 plugins · 23.5M total installs
How We Detect AffiliateWP – External Referral Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/affiliatewp-external-referral-links/assets/js/frontend.js/wp-content/plugins/affiliatewp-external-referral-links/assets/js/frontend.jsaffiliatewp-external-referral-links/assets/js/frontend.js?ver=