AffiliateWP – External Referral Links Security & Risk Analysis

wordpress.org/plugins/affiliatewp-external-referral-links

Allows affiliates to promote external landing pages by including the affiliate's ID or username in any outbound links to your e-commerce store.

800 active installs v1.2.2 PHP 7.4+ WP 5.2+ Updated Aug 27, 2025
affiliatewpcross-domain-trackingexternal-referral-linksexternal-sitespromote-other-sites
99
A · Safe
CVEs total1
Unpatched0
Last CVESep 22, 2025
Safety Verdict

Is AffiliateWP – External Referral Links Safe to Use in 2026?

Generally Safe

Score 99/100

AffiliateWP – External Referral Links has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 22, 2025Updated 7mo ago
Risk Assessment

The static analysis of affiliatewp-external-referral-links v1.2.2 indicates a generally strong security posture with several good practices observed. Notably, there are no dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. The absence of file operations, external HTTP requests, and a large attack surface with unprotected entry points is also positive. However, the complete lack of nonce and capability checks across all entry points, while the entry point count is zero, presents a potential concern. If any entry points were introduced in future versions or through other means, their lack of authentication and authorization checks would be a significant risk.

The vulnerability history shows one known CVE, which is currently patched. The nature of the past vulnerability, 'Cross-site Scripting,' combined with the lack of specific checks (nonce, capability) suggests a historical pattern where input sanitization and proper authorization might have been a weak point. While no current vulnerabilities are identified in this version, this history warrants attention. The lack of taint analysis results is neutral, as it suggests no obvious vulnerabilities of that type were found, but doesn't fully alleviate concerns given the lack of explicit security checks.

In conclusion, affiliatewp-external-referral-links v1.2.2 demonstrates good coding practices in several key areas, leading to a solid foundation. The primary weakness lies in the complete absence of nonce and capability checks, which, while not immediately exploitable due to the zero attack surface, represents a latent risk. The historical vulnerability also highlights the need for continued vigilance regarding input validation and authorization mechanisms.

Key Concerns

  • 0 nonce checks detected
  • 0 capability checks detected
Vulnerabilities
1

AffiliateWP – External Referral Links Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-53460medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

AffiliateWP – External Referral Links <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 22, 2025 Patched in 1.2.2 (5d)
Code Analysis
Analyzed Mar 16, 2026

AffiliateWP – External Referral Links Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped18 total outputs
Attack Surface

AffiliateWP – External Referral Links Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedaffiliatewp-external-referral-links.php:75
actionadmin_menuincludes\admin.php:10
actionadmin_initincludes\admin.php:11
filteraffwp_erl_sanitizeincludes\admin.php:12
actionwp_enqueue_scriptsincludes\class-affiliatewp-external-referral-links.php:165
filterplugin_row_metaincludes\class-affiliatewp-external-referral-links.php:168
Maintenance & Trust

AffiliateWP – External Referral Links Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 27, 2025
PHP min version7.4
Downloads19K

Community Trust

Rating60/100
Number of ratings2
Active installs800
Developer Profile

AffiliateWP – External Referral Links Developer Profile

Syed Balkhi

94 plugins · 23.5M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
795 days
View full developer profile
Detection Fingerprints

How We Detect AffiliateWP – External Referral Links

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliatewp-external-referral-links/assets/js/frontend.js
Script Paths
/wp-content/plugins/affiliatewp-external-referral-links/assets/js/frontend.js
Version Parameters
affiliatewp-external-referral-links/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about AffiliateWP – External Referral Links