AffiliateWP – Force Pending Referrals Security & Risk Analysis

wordpress.org/plugins/affiliatewp-force-pending-referrals

Force all referrals to a "pending" status.

600 active installs v1.2.0 PHP 7.4+ WP 5.2+ Updated May 8, 2025
affiliatewpforce-pendingmanual-referral-approvalpending-referralsreferral-status
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AffiliateWP – Force Pending Referrals Safe to Use in 2026?

Generally Safe

Score 100/100

AffiliateWP – Force Pending Referrals has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The static analysis of affiliatewp-force-pending-referrals v1.2.0 reveals a remarkably clean codebase with no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or capability checks. The code demonstrates strong security practices, with no dangerous functions utilized, all SQL queries employing prepared statements, and all output properly escaped. The absence of file operations, external HTTP requests, and any identified taint flows further strengthens its security posture. The plugin also has a clean vulnerability history, with no known CVEs recorded. This indicates a highly secure and well-developed plugin from a static analysis perspective, with a minimal attack surface and robust coding standards.

Vulnerabilities
None known

AffiliateWP – Force Pending Referrals Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AffiliateWP – Force Pending Referrals Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

AffiliateWP – Force Pending Referrals Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionaffwp_plugins_loadedaffiliatewp-force-pending-referrals.php:97
actionplugins_loadedaffiliatewp-force-pending-referrals.php:99
filterplugin_row_metaincludes\class-affiliatewp-force-pending-referrals.php:202
filteraffwp_auto_complete_referralincludes\class-affiliatewp-force-pending-referrals.php:208
filteraffwp_auto_complete_referralincludes\class-affiliatewp-force-pending-referrals.php:210
Maintenance & Trust

AffiliateWP – Force Pending Referrals Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 8, 2025
PHP min version7.4
Downloads15K

Community Trust

Rating0/100
Number of ratings0
Active installs600
Developer Profile

AffiliateWP – Force Pending Referrals Developer Profile

Syed Balkhi

94 plugins · 23.5M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
795 days
View full developer profile
Detection Fingerprints

How We Detect AffiliateWP – Force Pending Referrals

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliatewp-force-pending-referrals/assets/css/affiliatewp-force-pending-referrals.css/wp-content/plugins/affiliatewp-force-pending-referrals/assets/js/affiliatewp-force-pending-referrals.js
Script Paths
/wp-content/plugins/affiliatewp-force-pending-referrals/assets/js/affiliatewp-force-pending-referrals.js
Version Parameters
affiliatewp-force-pending-referrals/assets/css/affiliatewp-force-pending-referrals.css?ver=affiliatewp-force-pending-referrals/assets/js/affiliatewp-force-pending-referrals.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about AffiliateWP – Force Pending Referrals